Impact
Missing authorization checks in the Stylish Price List plugin allow attackers to use features that should be restricted to higher‑privileged users. The flaw creates a broken access control scenario where an unauthorized user can view or alter content beyond their intended scope, potentially escalating privileges or modifying restricted data.
Affected Systems
The vulnerability affects the Stylish Price List plugin by Design for WordPress. All released versions up to and including 7.2.2, including any earlier releases, are impacted. WordPress sites that have not upgraded beyond 7.2.2 are at risk.
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity, while the EPSS score of less than 1% signals a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker would need to identify a WordPress site running a vulnerable version and then exploit the broken access control to gain unauthorized access or modify content. Given the low EPSS, exploitation is uncommon, but the lack of hard permission checks could facilitate undetected privilege escalation.
OpenCVE Enrichment