Impact
The vulnerability is a missing authorization flaw in the Ultimate Member ForumWP plugin. Because access control security levels are incorrectly configured, an attacker can bypass role checks and gain unauthorized access to forum functions or administrative actions. This flaw is an instance of CWE-862: Authorization Bypass Through User-Controlled Key.
Affected Systems
The flaw affects the Ultimate Member ForumWP plugin versions up to 2.1.4, inclusive. The affected product is the ForumWP add‑on for WordPress, which has been released in versions from an unspecified earliest release through version 2.1.4.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity, reflecting the potential for unauthorized data access rather than full system compromise. The EPSS score of <1% suggests exploitation is unlikely, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a web‑based request to the plugin's endpoints; an attacker does not need elevated privileges beyond the ability to send crafted requests to the plugin. Because the issue stems from misconfigured access controls, exploitation would require the plugin to be installed and publicly accessible.
OpenCVE Enrichment