Impact
The Authorizer plugin for WordPress, versions up to and including 3.15.3, contains a flaw that allows an unauthenticated attacker to gain administrative privileges on a site. This vulnerability gives the attacker full control over site content, plugin installation, and configuration. The flaw results from insufficient authentication checks on privileged actions, allowing privilege escalation without needing a valid user session.
Affected Systems
The vulnerability affects the WordPress Authorizer plugin, listed under the vendor Paul Ryan. Versions up to and including 3.15.3 are susceptible; the fix is delivered in version 3.16.0 and later.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.8, indicating a high level of severity. EPSS is not available, and the exploit is not listed in CISA’s KEV catalog. The flaw permits privilege escalation without authentication, meaning an attacker can likely obtain administrative rights by sending crafted requests to the plugin’s interfaces. This can be performed remotely and without direct user interaction. Based on the description, the likely attack vector involves interacting with the plugin’s exposed HTTP endpoints, although the exact path is not explicitly described.
OpenCVE Enrichment