Impact
The Pubjet WordPress plugin, versions 5.4.8 and earlier, contains a vulnerability that allows an attacker with sufficient access to change subscriber settings. This flaw is a case of broken access control (CWE-862) and enables unauthorized configuration changes that could be used to alter site behavior or compromise user data. The impact is limited to configuration changes but could lead to further exploitation if combined with other weaknesses.
Affected Systems
WordPress installations running the Pubjet plugin version 5.4.8 or older are affected. The vulnerability applies to all sites that have not upgraded past this version threshold.
Risk and Exploitability
The CVSS score of 7.6 indicates a high severity level. Because EPSS data is not available and the vulnerability is not listed in the KEV catalog, the likelihood of widespread exploitation is uncertain, but the potential impact remains significant. Based on the description, the likely attack vector is through the WordPress administrative interface or exposed plugin controls, and an attacker would need access to a user account with permission to modify subscriber settings.
OpenCVE Enrichment