Impact
A missing authorization check in FluxBuilder MStore allows attackers to exploit incorrectly configured access control security levels, potentially accessing or modifying sensitive data and configuration without proper permission. This flaw is a CWE-862 Missing Authorization weakness.
Affected Systems
WordPress sites running FluxBuilder MStore API plugin version 4.18.4 or earlier are affected. Any site that has the plugin installed and enabled is at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of < 1% suggests a very low likelihood of exploitation in the near term, and the vulnerability is not listed in CISA KEV. The likely attack vector is inferred from the description; attackers would likely exploit this via web requests to the vulnerable plugin endpoints, bypassing expected authentication controls.
OpenCVE Enrichment