Impact
The affected plugin contains a missing authorization flaw that enables an attacker to bypass the configured access control and gain unauthorized access to sensitive data or modify entries. The bug is classified as CWE‑862, an improper authorization vulnerability. The impact is the potential for data exposure, tampering, and disruption of business operations through the manipulation of lawyer profiles and related information.
Affected Systems
The vulnerability affects the e‑plugins Lawyer Directory plugin for WordPress, from the first available version through version 1.3.3. Any WordPress site installing this plugin version or older is at risk.
Risk and Exploitability
The CVSS score of 7.6 indicates a high severity, while the EPSS score of less than 1 % suggests a low probability of exploitation at present. The vulnerability is not catalogued in the CISA KEV list. Based on the description, it is inferred that the attack vector involves HTTP requests to the plugin’s administrative endpoints, allowing a threat actor to exploit the missing authorization and manipulate data without proper authentication.
OpenCVE Enrichment