Impact
The WP ERP plugin for WordPress contains a missing authorization flaw that arises from incorrectly configured access control security levels. An attacker can exploit this weakness to bypass role‑based restrictions and access administrative functions or sensitive data that should be protected. The defect maps to CWE‑862, indicating a system is susceptible to exploitation through improper privilege checks.
Affected Systems
The vulnerability affects the weDevs WP ERP plugin for WordPress versions up to and including 1.16.7. Versions beyond 1.16.7 are not known to be impacted. Site operators using the plugin should verify the installed version and plan an upgrade.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the near term. The vulnerability is not listed in CISA KEV. Likely exploitation involves a web‑based attack path where an authenticated user with insufficient privileges can reach plugin endpoints that enforce inadequate access controls.
OpenCVE Enrichment