Impact
Missing authorization in RadiusTheme Team plugin (tlp‑team) allows users with insufficient privileges to perform privileged actions, such as manipulating team data or plugin settings. The flaw is a broken access control weakness defined by CWE‑862, which can lead to privilege escalation.
Affected Systems
WordPress sites running RadiusTheme Team plugin version 5.0.11 or earlier are affected. Any site that has an installed version in that range is at risk.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity. The EPSS score of less than 1% suggests a low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is via the web interface, requiring an authenticated session with at least minimal user rights to exploit the missing access control.
OpenCVE Enrichment