Impact
This vulnerability is a missing authorization flaw in the Mayosis Core plugin that lets attackers perform actions beyond the intended access level. An attacker could use an existing or newly created low‑privilege user account to view or modify content, change plugin settings, or access restricted areas of a WordPress site, thereby compromising confidentiality, integrity, and potentially availability of the site.
Affected Systems
WordPress sites running the TeconceTheme Mayosis Core plugin up to and including version 5.4.7 are affected.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate risk, and no EPSS data is available. The vulnerability is not listed in the CISA KEV catalog. Exploitation generally requires that the plugin is installed and that an attacker can log in to the site, using a legitimate user account to leverage the lax access controls. The likely attack vector is local to the WordPress installation, with no known public exploit.
OpenCVE Enrichment