Impact
The vulnerability is a missing authorization flaw that allows an attacker to bypass incorrectly configured access control levels within the Homey Core plugin. This results in a broken access control weakness (CWE-862) that can enable unauthorized access to restricted content or administrative functions of a WordPress site. The impact is elevating the user privileges of an attacker, potentially exposing sensitive data or allowing further exploitation if other weaknesses are present.
Affected Systems
Affected systems are WordPress sites running the Homey Core plugin from favethemes, with versions up to and including 2.4.3. All installations of Homey Core on these versions are vulnerable until the plugin is upgraded beyond 2.4.3.
Risk and Exploitability
The CVSS base score of 5.3 indicates a moderate severity, and the EPSS score is below 1%, suggesting a low probability of exploitation in the wild. Because the issue stems from missing authorization in the plugin code, the likely attack vector is a web-based request to a protected resource, such as an admin endpoint or a page that should be restricted. Although not listed in CISA’s KEV catalog, administrators should still address the issue promptly to eliminate the risk of privilege escalation on their sites.
OpenCVE Enrichment