Impact
The vulnerability allows an attacker to bypass access controls and view, create, or modify subscriber data within the WordPress WP ERP plugin. This broken access control can lead to unauthorized disclosure and alteration of subscriber personal information. The CVSS score of 6.5 indicates a moderate risk, reflecting the potential impact on confidentiality and integrity of subscriber data.
Affected Systems
The issue affects installations of the weDevs WP ERP plugin version 1.17.5 or earlier. Any WordPress site that has this plugin active and has not applied the patches provided by the vendor is potentially vulnerable.
Risk and Exploitability
With an EPSS score of less than 1% and not listed in the KEV catalog, the probability of exploitation remains low. Attackers can forge or manipulate HTTP requests targeting subscriber management endpoints, exploiting the broken access control to gain unauthorized access to subscriber data. The flaw arises from incomplete access‑control checks, allowing crafted requests to bypass legitimate permission checks.
OpenCVE Enrichment