Impact
A missing authorization flaw in the WPMU DEV Hustle plugin allows exploitation of incorrectly configured access control security levels. The vulnerability represents a broken access control weakness, identified as CWE-862.
Affected Systems
WordPress installations that use the WPMU DEV Hustle plugin through version 7.8.10.1 are affected. Site administrators should verify the plugin version in their WordPress dashboard and ensure they are not running a vulnerable release.
Risk and Exploitability
The vulnerability carries a CVSS score of 5.3, indicating moderate severity. The EPSS score is not available, suggesting limited publicly known exploitation data, and it is not listed in the CISA KEV catalog. The likely attack vector is an attacker with access to the WordPress admin interface or the ability to forge requests to the Hustle plugin’s endpoints, as the flaw permits bypassing incorrectly configured access controls.
OpenCVE Enrichment