Impact
The LifePress plugin for WordPress contains a missing authorization check that permits attackers to bypass intended access controls and exploit incorrectly configured security levels. This weakness, identified as CWE‑862, can allow unauthorized viewing, modification, or deletion of content or administrative settings managed by the plugin, potentially leading to data exposure or tampering.
Affected Systems
Ashan Perera’s LifePress plugin is affected, with all releases from the initial version through and including 2.2.1 vulnerable.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate risk, but the EPSS score of less than 1% suggests a low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. The attack is likely to occur via the WordPress admin or front‑end interfaces, where an attacker with sufficient access or credentials may invoke privileged actions without proper authorization. No exploit indicators have been reported publicly, and no critical exploit exists yet.
OpenCVE Enrichment