Impact
The CVE exposes a broken access control flaw in the WordPress RepairBuddy plugin versions up to 4.1132. Attackers who can authenticate as a subscriber may bypass the plugin's intended restrictions and gain unauthorized access to functions or data that should be reserved for privileged users. This violates the security principle of least privilege and can lead to unauthorized data exposure or modification. The flaw corresponds to CWE‑862, which highlights improper enforcement of access permissions.
Affected Systems
Affected systems are WordPress sites that have the RepairBuddy plugin installed by Webful Creations. The vulnerability exists in all releases with a version number of 4.1132 or earlier. Site administrators should verify whether the plugin version matches 4.1133 or later to ensure the issue is mitigated.
Risk and Exploitability
The CVSS score of 6.5 classifies the vulnerability as moderately severe, while the EPSS score of less than 1% suggests a very low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Exploitation would most likely occur through web requests to the plugin’s endpoints that lack proper access checks, allowing a legitimate user to leverage subscriber privileges to reach protected functionalities.
OpenCVE Enrichment