Impact
The vulnerability is an unauthenticated Insecure Direct Object Reference in Do Lasso plugin versions up to 358, allowing attackers to reference or modify protected resources without proper authorization checks. This could lead to the disclosure, alteration, or deletion of user data, compromising confidentiality, integrity, and potentially availability of the affected system. The weakness is classified as CWE-639.
Affected Systems
WordPress plugin Do Lasso provided by Lasso Analytics, Inc., affecting all installations of version 358 or earlier.
Risk and Exploitability
With a CVSS score of 6.5 the vulnerability is deemed medium severity. Exploitation is possible remotely without authentication, and no exploit probability is currently available; the vulnerability is not listed in CISA KEV. An attacker can craft requests containing arbitrary object identifiers to access or modify data beyond their permissions, making mitigation a priority.
OpenCVE Enrichment