Impact
The Lawyer Directory plugin for WordPress contains a missing authorization flaw that allows an attacker to override the intended access control settings. This weakness can let a user access data or perform operations that should be restricted, leading to potential data exposure or manipulation. The vulnerability is classified as a CWE-862, indicating a failure to enforce proper authorization logic.
Affected Systems
The affected product is the e-plugins Lawyer Directory plugin for WordPress. All installations running version 1.3.4 or earlier are vulnerable; versions newer than 1.3.4 are not affected.
Risk and Exploitability
The CVSS score of 7.3 marks this issue as high severity. The EPSS score is below 1%, suggesting that while the vulnerability is serious, it is unlikely to be widely exploited at this time. It is not listed in the CISA KEV catalog. Attackers likely need to access the web interface of the plugin, possibly with a valid authenticated session or by exploiting weakly protected endpoints, to exploit the missing access control checks. The exact attack path is not detailed in the advisory, but the weakness permits bypassing otherwise enforced authorization layers.
OpenCVE Enrichment