Impact
The flaw is a missing authorization check in the Saad Iqbal New User Approve WordPress plugin through version 3.2.3 that permits incorrect configuration of security levels to be abused. This allows attackers to create or approve new users without proper privilege verification, effectively elevating themselves or introducing rogue accounts and thereby compromising the confidentiality, integrity, and availability of the site due to the CWE-862 Access Control Failure classification.
Affected Systems
WordPress sites that have installed the Saad Iqbal New User Approve plugin with a version of 3.2.3 or earlier. The vendor is Saad Iqbal and the product is its New User Approve plugin used to manage user registration approvals.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of large‑scale exploitation. The vulnerability is not indexed in the CISA KEV catalog. Likely exploitation involves sending specially crafted HTTP requests to the plugin’s user approval or registration endpoints, and the attack would succeed even if the requester lacks normal user permissions. As the description signals a broken access control, it is inferred that authentication and authorization checks are bypassed, making the vulnerability potentially exploitable as an unauthenticated or low‑privilege attacker.
OpenCVE Enrichment