Impact
The Spectra plugin for WordPress contains a missing authorization flaw that allows attackers to bypass access controls. Exploitation of this flaw can lead to privilege escalation, permitting unauthorized users to perform actions normally restricted to higher‑privileged accounts. The weakness is categorized as CWE‑862, which highlights a failure to enforce correct authorization.
Affected Systems
Affected is the Brainstorm Force Spectra ultimate‑addons‑for‑gutenberg plugin for WordPress. Versions up to and including 2.19.22 are vulnerable, with no version prior to the initial release affected. Any WordPress installation using this plugin within the stated version range is at risk.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity vulnerability. EPSS is currently unavailable, and the issue is not listed in the CISA KEV catalog, suggesting limited public exploitation yet. However, the flaw can be leveraged by an attacker with access to managed WordPress environments—such as administrative portals or compromised user accounts—to bypass role restrictions. Because the flaw stems from incorrect configuration of access control security levels within the plugin, the attack is likely limited to actions that the plugin exposes to the interface, but it could enable further damage such as content manipulation or file uploads.
OpenCVE Enrichment