Impact
An IDOR flaw exists in the FAPI Member WordPress plugin up to version 2.2.30 that allows an authenticated user to supply a user-controlled key and access or modify resources belonging to another user. The weakness is a classic Authorization Bypass (CWE-639) that could lead to reading or altering sensitive data without the victim’s consent. The vulnerability does not grant arbitrary code execution, but it does allow an attacker to retrieve or change privileged content, potentially compromising confidentiality and integrity within the application.
Affected Systems
FAPI Business s.r.o. distributes the FAPI Member plugin for WordPress, and any site running a version up through 2.2.30 is vulnerable. The problem arises from incorrectly configured access controls, so any WordPress installation that has the plugin installed and has not upgraded past the stated version is susceptible.
Risk and Exploitability
The CVSS score of 5.3 suggests a moderate severity, while the EPSS score of less than 1% indicates very low exploitation probability at present. The vulnerability is not listed in the CISA KEV, implying it has not yet been widely exploited. An attacker would need to authenticate to the site, then craft requests with arbitrary object identifiers to traverse protected resources. The impact is limited to data belonging to other users and does not extend to system compromise or denial of service.
OpenCVE Enrichment