Impact
The WordPress Lawyer Directory plugin suffers an incorrect privilege assignment flaw that permits a user with limited permissions to obtain higher privileges. The vulnerability enables a non‑admin user to perform actions reserved for administrators, potentially leading to unauthorized content creation, configuration changes, or data exposure. The weakness corresponds to CWE‑266, highlighting improper management of privilege levels.
Affected Systems
The issue affects the e‑plugins Lawyer Directory plugin, versions from the unknown earliest release up to and including 1.3.3. WordPress installations running any of these plugin versions are susceptible. No other products or versions are listed as impacted.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while the EPSS score of less than 1% suggests exploitation probability is currently low but not negligible. As the vulnerability is not yet listed in CISA's KEV catalog, widespread active exploitation is not confirmed. The likely attack vector is via exploitation of a logged‑in user with restricted capabilities; the attacker would trigger the flaw through plugin interfaces or exploited functions. Because privilege escalation alters user access, an attacker can gain administrative rights, compromising the entire WordPress site.
OpenCVE Enrichment