Impact
The vulnerability is a broken access control flaw in the Wordable plugin for WordPress that allows a subscriber account to perform actions that should be restricted. Because of this weakness, an attacker could use a legitimate subscriber account or create one to access protected resources, potentially read sensitive data, create or edit content, or otherwise manipulate the application beyond intended permissions. The flaw is classified under CWE‑862, indicating that the authorization checks fail to enforce the correct access boundaries.
Affected Systems
Wordable plugin versions up to and including 8.2.10 installed on WordPress sites are affected. No additional version pinning is specified, so any release of the plugin before the 8.2.11 or later release is vulnerable.
Risk and Exploitability
With a CVSS score of 8.1 the vulnerability is regarded as high severity. The EPSS score is not published, and the issue is not listed in the CISA KEV catalog, but the impact remains significant. The attack vector is inferred to be a web‑based, authenticated attack that requires the attacker to obtain or model a subscriber account. Once in possession of such credentials, the attacker can exploit the broken checks without needing higher privileges or additional exploitation steps.
OpenCVE Enrichment