Impact
The vulnerability is a missing Authorization flaw, identified as CWE‑862, in the WP Reloaded ApplyOnline plugin that allows attackers to bypass the plugin’s configured access control security levels. The description does not clarify what specific functions become accessible once the intended authorization checks are circumvented, but the flaw permits gaining higher privileges within the plugin’s administrative interface.
Affected Systems
ApplyOnline, distributed by WP Reloaded, is affected in all releases from the earliest version through 2.6.7.6. Any WordPress site that installs this plugin at a version equal to or older than 2.6.7.6 is exposed to the flaw.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity level, while the EPSS score of < 1% suggests a very low exploitation probability. The vulnerability is not included in the CISA KEV catalog. Based on the description, it is inferred that exploitation requires sending crafted HTTP requests to the plugin’s protected administrative endpoints to bypass the authorization checks, with no additional prerequisites beyond access to these endpoints.
OpenCVE Enrichment