Impact
An Incorrect Privilege Assignment flaw in the LazyCoders LazyTasks WordPress plugin permits an attacker to elevate their access level. The plugin assigns administrative or higher capabilities without proper validation, enabling a malicious user to gain full control over the site’s content, settings, or user accounts. This vulnerability, classified as CWE-266, threatens confidentiality, integrity, and availability, especially if the attacker exploits an existing account or exploits weak session handling.
Affected Systems
The LazyTasks plugin by LazyCoders LLC, used within WordPress sites, is affected for all releases up to and including version 1.2.37. Any WordPress installation that has not updated this plugin remains vulnerable.
Risk and Exploitability
Based on the description, the likely attack vector is via crafted HTTP requests targeting the plugin’s endpoints, possibly requiring authenticated access. The CVSS score of 9.8 marks this issue as critical. Although the EPSS score is below 1%, implying a low empirical exploitation probability, the absence from CISA KEV does not reduce the risk for attackers who can reach the plugin’s endpoints—most likely through crafted HTTP requests or authorized user sessions. The privilege escalation potential can result in complete site takeover if the attacker succeeds.
OpenCVE Enrichment