Impact
The UiPress lite plugin for WordPress contains a Missing Authorization flaw (CWE‑862) that permits an attacker to bypass standard access controls, allowing privileged actions that should be reserved for authenticated administrators. This broken access control can enable an unauthorized user to view, modify, or delete site content and configuration settings, potentially compromising the entire site.
Affected Systems
The flaw affects UiPress lite installations by UiPress up through version 3.5.09. Any WordPress site running this plugin at version 3.5.09 or earlier is susceptible to the breach.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of widespread exploitation. The attack vector is likely remote, occurring via the WordPress web interface where the plugin resides; an attacker may require only minimal or no authentication to exploit the broken access controls. If successful, the attacker could gain full administrative access, enabling changes to site content, settings, or data.
OpenCVE Enrichment