Impact
The WebSamurai WordPress plugin contains a missing authorization flaw that allows attackers to exploit incorrectly configured access control security levels. This defect corresponds to CWE‑862 and can enable an attacker to perform actions or access content they are not supposed to, potentially compromising sensitive data or administrative functions on the site.
Affected Systems
The vulnerability affects the Kiera Howe WebSamurai WordPress plugin in all versions up to and including 1.0.7. Any WordPress installation that has installed this plugin is impacted, regardless of the WordPress core version or host environment.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, but the lack of an EPSS score or KEV listing suggests that no widespread exploitation is currently documented. Attackers would likely need to interact with the web application, implying a remote web‑based attack vector. The inability to enforce proper authorization could result in unauthorized data disclosure or privilege escalation within the site, but the impact is contingent upon the attacker’s ability to reach the vulnerable plugin endpoint.
OpenCVE Enrichment