Impact
The Link Whisper Premium plugin for WordPress has a broken access control flaw (CWE‑862) that allows a subscriber role to bypass normal authorization checks. The flaw permits a non‑administrator to reach plugin administrative screens or data endpoints that should be restricted, potentially exposing or altering plugin data that is normally protected.
Affected Systems
The affected product is the Link Whisper Premium WordPress plugin, versions up to 2.9.0. Any WordPress installation that has one of these versions installed is potentially vulnerable when users with subscriber or lower roles can access the plugin’s administrative screens or data endpoints. The vendor is LinkWhisper, and the solution is to upgrade to version 2.9.1 or later.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity, while the EPSS score of <1% reflects a very low probability of exploitation. The vulnerability is not cataloged in the CISA KEV list. The likely attack vector is logical: an attacker controlling a subscriber account can navigate the WordPress interface or invoke API endpoints tied to the plugin, triggering the unprotected actions without needing elevated CMS privileges. The combination of medium severity and low likelihood suggests that the threat is modest but should be mitigated promptly.
OpenCVE Enrichment