Impact
The Laser plugin for WordPress contains a missing authorization flaw that allows attackers to override its configured security levels. This defect enables unauthorized users to access or manipulate data and functions that should be restricted to privileged roles, potentially exposing sensitive content or compromising site integrity.
Affected Systems
The vulnerability affects the merkulove Laser WordPress plugin in all releases up to and including version 1.1.1. Users running any earlier installation are also exposed.
Risk and Exploitability
The CVSS score of 5.4 categorises the weakness as moderate, while an EPSS of less than 1% indicates a very low probability of exploitation at this time. The flaw is not currently listed in CISA’s KEV catalog. Based on the description, it is inferred that attackers would need to send crafted requests to the plugin's endpoints, and that any user role able to reach those endpoints, potentially including unauthenticated visitors, could exploit the flaw.
OpenCVE Enrichment