Impact
The vulnerability is an unauthenticated broken access control flaw (CWE‑862) in the WordPress POS Entegratör plugin versions 3.7.103 and earlier, enabling unauthenticated users to reach certain plugin features that are normally protected. The description does not list the specific functions that can be accessed, so the exact impact scope is not defined.
Affected Systems
The Gurmehub POS Entegratör plugin for WordPress is affected. Any installation running version 3.7.103 or earlier is vulnerable; sites using these plugin versions are therefore at risk.
Risk and Exploitability
The CVSS score of 8.2 indicates high severity. EPSS score is < 1%, so the exploitation probability is very low but non-zero. The vulnerability is not listed in CISA’s KEV catalog. Attackers can likely exploit the flaw by sending unauthenticated HTTP requests to the plugin’s endpoints; this inference follows from the description of the vulnerability as unauthenticated broken access control.
OpenCVE Enrichment