Impact
A missing authorization check allows the plugin to expose protected functionality to any user, potentially enabling privilege escalation or unauthorized content changes. This flaw is classified as CWE‑862 and can lead to a significant breach of confidentiality, integrity, or availability for the affected WordPress installation.
Affected Systems
The vulnerability impacts the WordPress ElementCamp plugin, third‑party product by wpdive, in all releases up to and including version 2.3.2. Any site that has not upgraded beyond this version is at risk.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% shows a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Attackers would likely use the web interface to send crafted requests to the plugin’s endpoints, exploiting the incorrect access control configuration. No prerequisite conditions beyond site access are stated.
OpenCVE Enrichment