Impact
The LCweb PrivateContent plugin for WordPress contains an Incorrect Privilege Assignment flaw that allows a lower‑level user to assume higher‑level or administrator privileges. This flaw compromises control over site content and functions by enabling unauthorized privilege escalation.
Affected Systems
The LCweb PrivateContent plugin for WordPress, version 9.9.2 and earlier, is affected. All releases from the initial version up to and including 9.9.2 contain the privilege assignment flaw.
Risk and Exploitability
The CVSS score of 9.8 signals a critical severity for this flaw. The EPSS score of < 1% indicates a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog, implying no publicly confirmed exploitation yet. The attack vector most likely involves a legitimate user’s interaction with the plugin, as the vulnerability arises from incorrect privilege assignment during normal operation.
OpenCVE Enrichment