Impact
MailerPress plugin contains an incorrect privilege assignment flaw. The vulnerability arises when the plugin does not correctly restrict the assignment of roles, allowing an attacker to elevate their privileges. This can lead to unauthorized access to administrative functions, data exposure, or further exploitation. The weakness is mapped to CWE-266, which denotes unauthorized privilege escalation.
Affected Systems
The affected product is the MailerPress plugin developed by the MailerPress Team. Versions from the earliest release through 2.0.2 are vulnerable; no specific earlier version is quoted, so all releases up to and including 2.0.2 must be considered at risk.
Risk and Exploitability
The CVSS score of 8.8 signals a high severity vulnerability. The EPSS score at less than 1% indicates that, while the exploitation likelihood is low, it remains possible and has not been catalogued by CISA KEV. Based on the description, it is inferred that an attacker needs some level of authenticated access to the WordPress site, though the flaw may enable escalation from a lower role to higher privileges. Once escalated, the attacker can manipulate site content, gain administrative control, or exfiltrate sensitive information.
OpenCVE Enrichment