Impact
A missing authorization flaw allows a user to perform privileged actions within the Precious Metals Automated Product Pricing – Pro WordPress plugin. The vulnerability is classified as CWE‑862.
Affected Systems
The nfusionsolutions Precious Metals Automated Product Pricing – Pro plugin, all releases from the initial version through and including 4.0.5, is affected.
Risk and Exploitability
The CVSS score of 5.3 indicates medium risk, while the EPSS score of less than 1% suggests a low probability of widespread exploitation. The issue is not listed in the CISA KEV catalog. Based on the description, the likely attack vector requires an authenticated WordPress user; the attacker would invoke privileged plugin functions that are intended to be restricted.
OpenCVE Enrichment