Impact
The vulnerability is a broken access control flaw in the ProLancer Element plugin for WordPress, affecting all versions up to and including 1.4.8. It allows a user with a subscriber role to access or modify content or plugin features that should be restricted, thereby compromising the integrity and confidentiality of the site. The flaw is classified as CWE‑862, which describes improper authorization.
Affected Systems
WordPress sites that have the ProLancer Element plugin (ThemeBing:ProLancer Element) installed at version 1.4.8 or earlier are affected. No other versions or plugins are mentioned as impacted.
Risk and Exploitability
The vulnerability has a CVSS score of 7.1, indicating a high severity impact. No EPSS score is available, and it is not listed in the CISA KEV database. Based on the description, the likely attack vector is through a logged‑in subscriber account; an attacker who has any subscriber access could exploit the flaw to bypass authorization checks and access disallowed content or functions. Because the flaw requires authentication, the attack surface is limited to WordPress users, but the potential to compromise or alter site data is significant.
OpenCVE Enrichment