Impact
The Block User Account WordPress plugin before version 2.0.1 contains a logic flaw that fails to enforce account blocks on all authentication paths. A user who has been blocked but still holds an application password created prior to the block can authenticate against the REST API and access content with the full role permissions that the block should eliminate.
Affected Systems
The vulnerability affects the Block User Account WordPress plugin for all releases earlier than 2.0.1 on any WordPress site that uses the plugin. Users with blocked accounts and existing application passwords are impacted.
Risk and Exploitability
The EPSS score is less than 1%, indicating a very low probability of exploitation. The CVSS score of 5.4 indicates moderate severity. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to obtain an application password belonging to a blocked user, which could occur if an attacker compromises the site or reuses credentials. The vulnerability is exploitable via the REST API using the revoked credentials, and the EPSS score suggests that exploitation is not common but possible.
OpenCVE Enrichment