Impact
The vulnerability is a missing authorization flaw in the WP Mailster plugin that permits attackers to exploit incorrectly configured access control settings. Because of the broken access control, a user lacking proper permissions can access privileged plugin functions, potentially viewing or manipulating stored email data. The weakness, identified as CWE-862, allows unauthorized users to bypass normal WordPress role checks and achieve unintended privilege escalation within the plugin scope.
Affected Systems
Affected systems include any WordPress installation running the WP Mailster plugin version 1.9.0.0 or earlier. The official product name is WP Mailster, and the vulnerability impacts all versions from the initial release up to and including 1.9.0.0.
Risk and Exploitability
The CVSS base score of 5.3 classifies the flaw as medium severity. EPSS is not available, so current exploitation potential is uncertain, yet the lack of a KEV listing implies no known large‑scale exploitation. Based on the nature of a broken access control flaw, the most likely attack vector is remote, where a logged‑in user could send crafted requests to access disallowed functions. An attacker would need to authenticate with a standard user account or exploit an existing authenticated session to benefit from the vulnerability.
OpenCVE Enrichment