Impact
Merkulove’s Worker for WPBakery plugin contains a missing authorization flaw that enables attackers to exploit incorrectly configured access control levels. The vulnerability allows an unauthenticated or minimally privileged user to perform actions reserved for higher‑privileged roles, potentially modifying plugin data or triggering unintended behaviors. The weakness is identified as CWE‑862, highlighting the absence of proper access checks.
Affected Systems
WordPress installations using the Worker for WPBakery plugin version 1.1.1 or earlier are affected. The issue applies to all instances where the plugin is active, regardless of other configuration settings.
Risk and Exploitability
The CVSS base score of 5.4 signifies a moderate impact, yet the sub‑1% EPSS score indicates a very low likelihood of public exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. A likely attack vector is a remote HTTP request to a vulnerable plugin endpoint, inferred from the nature of the authorization bypass.
OpenCVE Enrichment