Impact
The plugin contains a missing authorization flaw that allows an attacker to bypass configured access control levels and gain unauthorized access to protected videochat resources. This flaw enables the exploitation of restricted content and may compromise the confidentiality of video streams and chat logs, while also potentially affecting availability if the service is misused.
Affected Systems
All installations of the VideoWhisper.com Paid Videochat Turnkey Site plugin up to and including version 7.3.23 are affected. The plugin is deployed on WordPress sites and can be obtained from the standard WordPress plugin repository.
Risk and Exploitability
With a CVSS score of 5.3 the vulnerability is rated moderate. The EPSS score is not available and the issue is not listed in the CISA KEV catalog, indicating that no confirmed exploits have been reported. Nevertheless, the lack of authentication checks means that a simple HTTP request to a protected endpoint can succeed, so the risk is driven by misconfiguration rather than sophisticated attack methods.
OpenCVE Enrichment