Impact
The eRoom WordPress plugin for DigitalME contains a broken access control flaw that allows a user with subscriber privileges to access or manipulate content and functions that should be limited to higher‑privileged roles. The vulnerability is a classic example of inadequate permission checks, falling under CWE‑862. Because the code bypasses standard role verification, an attacker can expose sensitive data, create or modify meetings, or otherwise perform actions that would normally require stronger authentication.
Affected Systems
The flaw affects any installation of the DigitalME eRoom plugin for WordPress that is version 1.7.1 or earlier. Users running these legacy versions are subject to the same broken access restrictions, regardless of the tenant or hosting environment.
Risk and Exploitability
With a CVSS score of 5.4 the vulnerability is classified as moderate severity. The EPSS score is less than 1%, indicating a very low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that attackers would need a valid subscriber account; once logged in, the access‑control weakness allows them to reach plugin endpoints or administrative that should be gated. No additional authentication, privilege escalation, or network-based exploitation steps are required beyond the existence of a legitimate subscriber credential.
OpenCVE Enrichment