Impact
The flaw is a missing authorization check in wpforchurch Sermon Manager that allows users to perform privileged actions that are not intended for them. The plugin’s security levels are incorrectly configured, so someone who should not be able to publish, edit, or delete sermons could gain those capabilities. This is a classic missing‑authorization weakness, identified as CWE‑862.
Affected Systems
WordPress sites that have the Sermon Manager plugin installed at any version through 2.30.0 are affected. The vulnerable code is part of the wpforchurch product, so any WordPress installation using version 2.30.0 or earlier of this plugin is potentially exploitable.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity for an unauthorized access flaw, while an EPSS score of less than 1% suggests the likelihood of exploitation is currently low but not negligible. The vulnerability is not listed in the CISA KEV catalog. Exploitation would most likely occur through the plugin’s administrative endpoints, requiring either the presence of a user account with a sufficiently high role or misconfigured plugin settings that expose privileged functions to broader audiences.
OpenCVE Enrichment