Impact
This vulnerability in the WC Lovers WCFM Membership plugin allows an attacker to bypass authorization controls and access functions that should be restricted to authorized users. The missing authorization check can let attackers view or alter membership data, plugin settings, or perform actions normally reserved for administrators or privileged roles, potentially leading to data leakage or unauthorized configuration changes.
Affected Systems
The issue affects the WC Lovers WCFM Membership plugin for WordPress versions up to and including 2.11.11. All installations using any version from the initial release through 2.11.11 are vulnerable; the plugin is fixed as of version 2.12.0.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity impact. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited visibility of active exploitation reports. The likely attack vector, inferred from the description of a missing authorization check, involves sending unauthorized HTTP requests to plugin‑protected endpoints; an attacker would need either public access to the site or to compromise a user's credentials to exploit the weakness.
OpenCVE Enrichment