Impact
The vulnerability is a missing authorization flaw in the myCred WordPress plugin that permits attackers to exploit incorrectly configured access control security levels. It allows an attacker to bypass normal user permissions and gain unauthorized access to protected functionality or data. The weakness is categorized as CWE‑862, indicating an authorization failure.
Affected Systems
The issue affects every installation of the myCred plugin version 3.1.2 and earlier by Saad Iqbal. Any WordPress site using these plugin versions is susceptible, regardless of the overall WordPress version.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity. The EPSS score of less than 1% suggests the likelihood of exploitation is low at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves an authenticated user who can interact with the plugin’s endpoints or a user who gains temporary elevated permissions through another vulnerability. Exploitation would enable the attacker to access or modify protected data or perform privileged actions beyond their assigned role.
OpenCVE Enrichment