Impact
This flaw permits an attacker with subscriber privileges to bypass critical access controls in the WordPress myCred plugin. The weakness (CWE-862) allows impersonation of more powerful roles, leading to unauthorized viewing, modification, or deletion of user balances and other protected data. The CVSS score of 6.5 categorizes the impact as moderate, indicating significant potential damage to confidentiality and integrity of user accounts.
Affected Systems
All installations of the WordPress myCred plugin version 3.0.3 or earlier are affected. The issue does not impact later versions such as 3.0.4 and above.
Risk and Exploitability
The EPSS score of less than 1% suggests that automated exploitation is unlikely at this time, and the vulnerability is not currently listed in the CISA KEV catalog. Nevertheless, the risk is non‑negligible because an attacker only needs to authenticate as a subscriber or impersonate one. Once the access‑control checks are circumvented, the attacker can exercise functions that are normally reserved for privileged users. The likely attack vector is through web requests to the plugin’s exposed API endpoints, using standard HTTP methods.
OpenCVE Enrichment