Impact
An authentication bypass flaw exists in the Studio99 WP Monitor plugin for WordPress. The missing authorization weakness (CWE-862) allows an attacker to access functionality that should be restricted. This can lead to exposure or alteration of plugin data and potentially influence the broader WordPress site if the attacker is able to manipulate plugin settings or perform administrative actions.
Affected Systems
The vulnerability affects all releases of the Studio99 WP Monitor plugin from the first version through version 1.0.3. No specific sub‑versions are noted as unaffected, so it is assumed that all older releases up to and including 1.0.3 are susceptible.
Risk and Exploitability
The CVSS base score of 5.3 indicates a moderate severity vulnerability. With an EPSS score less than 1 %, the likelihood of exploitation in the near future is low, and the vulnerability is not listed in the CISA KEV catalog. The flaw is accessed via the plugin’s web interfaces; the likely attack vector is a web request sent to the affected endpoints without requiring prior authentication.
OpenCVE Enrichment