Impact
The vulnerability is a broken access control flaw that permits users with subscriber privileges to access or modify areas of the ShopLentor Pro plugin that are intended for higher‑level roles. The description limits the impact to actions that subscribers can perform; it does not claim additional data exposure or extensive privilege escalation.
Affected Systems
WooLentor’s ShopLentor Pro plugin versions up to and including 2.8.5 are affected. Any WordPress installation that has one of these vulnerable versions installed is at risk.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the near term. Because the flaw requires authenticated subscriber access, the attack vector is likely confined to users who have legitimate access to the site. The plugin is not listed in the CISA KEV catalog.
OpenCVE Enrichment