Impact
The WP Easy Pay plugin for WordPress suffers from an authorization bypass that allows any authenticated user with a Subscriber role or higher to permanently delete arbitrary posts, pages, and custom post types, or change any published content to draft status. Because the plugin does not correctly verify user permissions before executing these actions, a malicious actor can destroy content or disrupt a site’s public-facing pages. The flaw is a classic instance of CWE‑862, causing loss of data integrity and availability rather than confidentiality compromise.
Affected Systems
WordPress sites running the WP Easy Pay – Payment and Donation Form Builder for Square plugin, any version up to and including 4.5.0, are vulnerable. The affected code exists in the core plugin file, and the issue applies to all installations that have kept the plugin on the default subscriber role.
Risk and Exploitability
The CVSS v3.1 score of 4.3 categorizes this as a moderate severity vulnerability. The EPSS score of <1% indicates a very low exploitation likelihood under current threat intelligence. The flaw is not listed in the CISA KEV catalog, further suggesting limited public exploitation. However, because the attack vector requires only an authenticated session with subscription-level access, any user able to access the WordPress admin area can exploit the bug, which makes the requirement minimal from the attacker’s perspective.
OpenCVE Enrichment