Impact
The WordPress eRoom plugin contains an unauthenticated broken authentication flaw that allows an attacker to bypass login controls, potentially gaining unauthorized access to sensitive administrative functions such as account management, meeting scheduling, and configuration settings. The weakness stems from improper enforcement of authentication checks and is classified as CWE-288. An attacker could exploit this flaw without prior credentials, enabling them to read, modify, or delete content and compromise user data or service availability.
Affected Systems
The vulnerability affects DigitalME’s eRoom plugin for WordPress, versions 1.7.1 and earlier. Users running any of these versions on their WordPress installations are exposed to the authentication bypass unless upgraded to a newer release.
Risk and Exploitability
The CVSS base score of 7.3 indicates a moderate to high severity level. While the EPSS score is not available, the lack of a KEV listing suggests that this vulnerability has not yet been widely exploited publicly, but it remains a serious threat given its authentication bypass nature. Attackers could discover the flaw through web reconnaissance or administrative interfaces, and exploitation requires no special privileges or advanced skills, so the risk is significant for any site that deploys the vulnerable plugin.
OpenCVE Enrichment