Impact
The vulnerability allows attackers to bypass authentication by exploiting an alternate path or channel in the LearnPress – Sepay Payment plugin. This flaw enables unauthorized users to access protected areas or perform actions reserved for authenticated users, potentially compromising confidentiality and integrity of site data.
Affected Systems
The flaw affects all installations of the ThimPress LearnPress – Sepay Payment plugin for WordPress with a version no higher than 4.0.0. Any site that has not updated beyond this release is susceptible.
Risk and Exploitability
The CVSS score of 7.5 indicates a moderately high severity. The EPSS score is below 1%, suggesting low current exploit prevalence, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, through a web request to the plugin’s alternate authentication path, requiring no special privileges. An attacker who succeeds could gain unauthorized access, elevate privileges, or manipulate site content.
OpenCVE Enrichment