Impact
The vulnerability is a broken access control flaw in the Solace Extra WordPress plugin. An attacker could exploit unauthorized access to subscriber management functions, potentially viewing or modifying subscriber data. The issue arises from improper access checks (CWE‑862).
Affected Systems
The Solace Extra plugin for WordPress versions 1.6.0 and earlier are affected. Users running these versions on any WordPress installation should review the plugin version.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. EPSS is unavailable, and the vulnerability is not listed in CISA KEV. The likely attack vector is through HTTP requests to the plugin’s endpoints, implying that an attacker could send crafted requests that bypass missing access checks. Successful exploitation could enable unauthorized data disclosure or modification within the plugin’s scope. The lack of a publicly disclosed exploit and absence from KEV suggest that exploitation is feasible but currently unobserved.
OpenCVE Enrichment