Impact
The updated description reveals a missing authorization flaw that permits users to perform privileged actions within the Precious Metals Automated Product Pricing – Pro WordPress plugin, including modifying product pricing or accessing sensitive configuration data. The vulnerability is classified as CWE‑862.
Affected Systems
The nfusionsolutions Precious Metals Automated Product Pricing – Pro plugin, all releases from the initial version through and including 4.0.5, is affected.
Risk and Exploitability
The CVSS score of 5.3 indicates medium risk, while the EPSS score of less than 1% suggests a low probability of widespread exploitation. The issue is not listed in the CISA KEV catalog. Based on the updated description, the flaw appears exploitable via authenticated WordPress accounts, allowing them to invoke privileged plugin functions that are intended to be restricted.
OpenCVE Enrichment