Impact
The Leadpages Plugin for WordPress contains a broken access control flaw that allows an attacker to bypass intended authorization checks. This weakness, identified as CWE-862, can enable unauthorized users to view or manipulate content and settings that should be protected, potentially exposing sensitive site data or affecting site integrity.
Affected Systems
The vulnerability affects the Leadpages WordPress plugin version 1.1.3 and earlier. Site administrators should verify whether an affected version is in use and note that any installation running 1.1.3 or older is susceptible.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity issue, and the EPSS score of less than 1% suggests a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, indicating no widely known exploits. Nonetheless, because the flaw permits unauthorized access, it remains a relevant risk to sensitive data and site functionality.
OpenCVE Enrichment