Impact
The Stratum plugin for WordPress has a missing authorization check in all releases up to version 1.6.1. This flaw allows attackers to perform actions or view data they are not permitted to access, potentially exposing sensitive information or altering site content. The weakness is categorized as CWE‑862: Missing Authorization.
Affected Systems
The vulnerability affects the Stratum plugin developed by JetMonsters. All versions from the initial release through 1.6.1 are impacted. No other products are known to be affected.
Risk and Exploitability
The flaw carries a CVSS score of 4.3, reflecting moderate severity, and an EPSS score of less than 1%, indicating a very low current probability of exploitation. It is not listed in the CISA KEV catalog. Because the attack surface is limited to users who have access to the WordPress interface, the likely attack vector is through the web interface where a user without proper privileges can trigger the unauthorized behavior. Without additional authority, exploitation requires the attacker to gain some form of authenticated access to the site.
OpenCVE Enrichment