Impact
An unauthenticated user can exploit a flaw in the Kadence WooCommerce Email Designer plugin to elevate privileges on a WordPress site. The vulnerability allows a non‑authenticated attacker to gain higher‑level permissions, potentially enabling full control over the WordPress administration interface, modification of site content, or deployment of additional malicious plugins.
Affected Systems
The affected product is the Kadence WooCommerce Email Designer plugin for WordPress, sold by Nexcess. Versions up to and including 1.5.19 are vulnerable.
Risk and Exploitability
The CVSS score of 9.8 indicates an extremely severe threat. Because the EPSS score is not available, the exact likelihood of exploitation is unknown, but the lack of a KEV listing suggests no widely reported attacks yet. The likely attack vector is via an unauthenticated request to a privileged operation in the plugin, as the vulnerability stems from an authorization bypass (CWE‑862).
OpenCVE Enrichment