Impact
The vulnerability is an unauthorized access control flaw present in Civi Framework versions up to 2.2.0. It allows a non‑authenticated user to traverse the plugin’s protected endpoints and read or alter data that should be restricted. The weakness is classified as CWE‑862 and could compromise the confidentiality and integrity of the information handled by the plugin, though it does not provide remote code execution.
Affected Systems
The exposed product is the WordPress Civi Framework plugin, maintained by uxper. Any site running version 2.2.0 or earlier is potentially affected. Administrators should verify the plugin version used on their installation and plan to move to a newer, patched release if available.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, while the EPSS figure of less than 1% signals a low likelihood of current exploitation. The vulnerability is not listed in CISA’s KEV catalog, suggesting no known active exploitation in the wild. An attacker merely needs web‑level access to the site and can craft HTTP requests targeting the plugin’s endpoints to exploit the broken access control without requiring elevated privileges on the underlying system.
OpenCVE Enrichment