Impact
Missing authorization in the LC Wizard plugin permits an attacker who can access the plugin’s admin interface to change its configuration settings. This lack of proper access control enables an unauthorized user to alter or disable plugin features, potentially compromising the site’s functionality and security.
Affected Systems
All installations of the Niaj Morshed LC Wizard plugin with a version equal to or older than 2.1.1 are vulnerable. The issue occurs in the plugin as distributed for WordPress and affects any site that has not applied a later update.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, but the EPSS score of less than 1% suggests that the likelihood of automated exploitation is currently low. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is through the web interface exposed by WordPress, allowing remote exploitation without elevated privileges. An attacker with web access to the site could manipulate settings without proper authentication checks, thereby elevating privileges within the WordPress environment.
OpenCVE Enrichment