Impact
The CMP WordPress plugin in versions prior to 4.1.18 fails to restrict the set of option names that can be imported through an AJAX call. An editor who has been given access to the plugin via the admin‑bar controls can use this endpoint to update any WordPress option value, including those that control user roles or capabilities. By altering these options an attacker can elevate a user from Editor to Administrator, effectively gaining full control over the site.
Affected Systems
The vulnerability affects the CMP WordPress plugin, any site that has installed this plugin with a version earlier than 4.1.18. The impact is confined to installations where the site administrator has granted the Editor role permission to use the CMP WordPress plugin’s admin‑bar controls.
Risk and Exploitability
The flaw can be exploited remotely by presenting an authenticated request to the plugin’s AJAX endpoint. No code execution is required beyond the Editor role. The CVSS score of 7.2 indicates high severity. The EPSS score of <1% and the lack of listing in CISA’s KEV catalog imply a low probability of exploitation, yet the vulnerability still allows an attacker to elevate to Administrator if Editor access is granted to the CMP plugin’s admin‑bar interface. Once elevated, full control of the WordPress site can be achieved, making this a critical risk for affected installations.
OpenCVE Enrichment