Impact
The vulnerability is an improper access control flaw (CWE‑862) that permits users who lack sufficient privileges to access or modify functionality of the Sugar Calendar (Lite) plugin. An attacker could view or alter calendar events, export data, or perform administrative actions without authorization, leading to confidentiality and integrity impact.
Affected Systems
The issue affects the Sugar Calendar (Lite) plugin developed by Syed Balkhi for WordPress installations that are running any release through 3.9.1. The plugin is available as a free or lite version on the WordPress plugin repository. The affected range is noted as n/a through 3.9.1, indicating all versions prior to 3.9.2 are potentially vulnerable.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. Exploit probability according to EPSS is less than 1 %, implying it is unlikely to be widely exploited at present. The vulnerability is not listed in the KEV catalog, and no public exploit is known. Based on the description, it is inferred that an attacker could access or modify calendar events or configuration if they can reach the plugin interface, but the required authentication level is not specified in the CVE data. The potential impact is therefore limited to the data and settings managed by the plugin.
OpenCVE Enrichment