Impact
Based on the description, the missing authorization flaw enables an attacker to bypass the intended access controls. Based on the description, without proper restrictions the attacker could access administrative functions or confidential data stored by the plugin. Based on the description, this failure could lead to unauthorized disclosure or modification of plugin settings, potentially compromising the integrity of the website.
Affected Systems
WordPress sites deploying the Strategy11 Team Business Directory plugin before version 6.4.20 are affected. All releases from the earliest available version up to and including 6.4.19 contain this broken access control issue.
Risk and Exploitability
The CVSS score of 4.9 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA's KEV catalog. Based on the description, it is inferred that attackers might exploit the flaw via web requests targeting endpoints that expect elevated privileges, and that the plugin code removes the necessary authorization check, potentially allowing any authenticated or possibly unauthenticated user to invoke sensitive functions.
OpenCVE Enrichment