Impact
The fitness‑trainer plugin for WordPress, in all releases up to and including version 1.7.1, contains a missing authorization check that lets an attacker access restricted functionality. The flaw is classified as CWE‑862. In practice, a malicious actor can perform actions normally reserved for privileged users without providing valid credentials.
Affected Systems
Affected systems are WordPress installations that have the e‑plugins fitness‑trainer plugin installed at any version ≤ 1.7.1. The vulnerability applies to all sites that rely on the plugin’s administrative features.
Risk and Exploitability
The CVSS score of 7.3 signals high severity, while the EPSS score of less than 1 % shows that exploit attempts are rare at present. It is not listed in the CISA KEV catalog. The attack vector is remote: an adversary can send crafted requests to the plugin’s endpoints to bypass authorization. Because the flaw allows misuse of the plugin’s privileged functions, the impact could include unauthorized configuration changes, data leakage, or persistence.
OpenCVE Enrichment