Impact
Missing Authorization vulnerability in the e-plugins Final User plugin permits attackers to exploit incorrectly configured access control security levels. Because the plugin does not properly enforce user permissions, an attacker can gain unauthorized access to restricted functionality, potentially modifying user data, changing configuration settings, or extracting sensitive information.
Affected Systems
WordPress sites using the Final User plugin from the earliest released version up through version 1.2.5 are affected. The vulnerability is present in any installation of Final User plugin version 1.2.5 or earlier.
Risk and Exploitability
The CVSS score of 7.3 indicates a high severity, while the EPSS score of less than 1% suggests a low probability of exploitation at current time. The vulnerability is not listed in the CISA KEV catalog. Based on the description it is inferred that the attack vector is via the plugin’s web interface, potentially requiring an authenticated user or misconfigured access levels. An attacker who can trigger the bypassed privilege checks could elevate privileges or compromise the plugin’s configuration, potentially leading to broader site compromise.
OpenCVE Enrichment