Impact
The flaw is an incorrect privilege assignment that allows a user with lower permissions to gain higher roles without proper authorization. Identified as CWE-266, this flaw enables privilege escalation by assigning elevated privileges directly within the MailOptin plugin. The impact is that an attacker could potentially acquire administrator access and control over the WordPress site, compromising confidentiality, integrity, and availability of site content and configuration.
Affected Systems
The affected product is the properfraction MailOptin plugin for WordPress. All installations using version 1.2.77.3 or earlier are impacted; no other vendors or product versions are listed as affected.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity. The EPSS score of less than 1% suggests a low probability of exploitation in the near term, and the vulnerability is not listed in CISA KEV. Based on the description, the likely attack vector involves an authenticated user who has plugin access exploiting the privilege assignment flaw to elevate their own role level.
OpenCVE Enrichment