Impact
The WaMate Confirm – Order Confirmation plugin for WordPress contains a missing authorization check that allows any authenticated user with subscriber-level or higher access to invoke functions for blocking and unblocking phone numbers. This flaw is a classic example of improper authorization (CWE‑862) and grants attackers the ability to alter contact information that should be restricted to administrators, potentially disrupting communications for the site’s users or customers.
Affected Systems
WordPress installations using the WaMate Confirm – Order Confirmation plugin, versions up to and including 2.0.1, distributed by sm_rasmy.
Risk and Exploitability
The vulnerability has a CVSS score of 5.3, indicating moderate severity, and an EPSS score of less than 1%, suggesting a low likelihood of exploitation in the wild. It is not currently listed in the CISA KEV catalog. Exploitation requires the attacker to be authenticated in the WordPress site, typically via a subscriber or higher role, and can be performed through the web interface or API endpoints provided by the plugin. The attack can iterate on the ability to block or unblock any phone number stored by the plugin, thereby affecting service availability and potentially enabling social engineering attacks.
OpenCVE Enrichment