Impact
The vulnerability is a missing authorization flaw in the WofficeCore plugin for WordPress. It allows an attacker who can reach the plugin’s administrative functions to perform actions or view data beyond their intended permissions. This broken access control can expose sensitive content or enable unauthorized configuration changes. The weakness is classified as CWE‑862.
Affected Systems
The affected product is the Woffice Core plugin developed by WofficeIO, used within WordPress sites. All releases up through version 5.4.30 are vulnerable, including any earlier builds that fall in that range. There is no information indicating that the issue has been fixed in later releases.
Risk and Exploitability
The CVSS score of 5.3 suggests a moderate impact when exploitation succeeds. The EPSS score of less than 1% indicates a low probability of real-world exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Likely, the attacker would need access to a user role with some privileges or exploit an improperly configured WordPress role, which could allow them to use the plugin’s privileged endpoints. Without elevated permissions, the exploitation surface remains limited, and the risk is mitigated by proper role configuration.
OpenCVE Enrichment