Impact
The Datalogics Ecommerce Delivery plugin for WordPress contains an unauthenticated privilege escalation flaw in all releases up to 2.6.62. Attackers can exploit the vulnerability to gain elevated privileges within the WordPress environment, allowing them to modify site content, configuration, and potentially add additional malicious code. The impact extends to loss of confidentiality, integrity, and availability of the entire site.
Affected Systems
The vulnerable product is the WordPress Datalogics Ecommerce Delivery Plugin, with affected versions 2.6.62 and earlier. No other WordPress components or plugins are listed as affected.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity, while an EPSS score of less than 1% implies a low likelihood of exploitation at the time of this analysis. The vulnerability is not yet listed in the CISA KEV catalog. The likely attack vector is network‑based via the plugin’s web interface, as the flaw can be triggered by unauthenticated users. Despite the high severity, the current exploitation probability is low, but immediate remediation is essential to prevent potential compromise.
OpenCVE Enrichment