Impact
The Claspo Popup Builders plugin contains a missing authorization flaw that allows any authenticated site user to access administrative functionality intended for privileged users. This unauthorized access can enable attackers to create, modify, or delete pop‑up content and potentially expose configuration data, compromising the integrity and confidentiality of the web application. The weakness is identified as CWE-862, indicating insufficient access control checks during plugin operations.
Affected Systems
WordPress installations running the Claspo – Popups, Spin the Wheel & Email Capture plugin, version 1.0.7 or earlier. The vulnerability applies to all unspecified earlier releases as it effects all builds from the initial release up to and including 1.0.7.
Risk and Exploitability
The flaw carries a CVSS score of 5.3, reflecting a medium severity level. The EPSS score of less than 1% suggests that exploit attempts are rare, and the vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation. The attack vector is likely the plugin’s web interface, requiring only standard user authentication; thus, any authenticated user without appropriate role checks could exploit the flaw. The overall risk is moderate, but the potential impact on site content and data integrity warrants timely remediation.
OpenCVE Enrichment