Impact
This vulnerability is a broken access control flaw in the WordPress Cyr to Lat reloaded – transliteration of links and file names plugin from Themeisle. It allows an authenticated user with the Subscriber role to bypass the access checks that should restrict plugin functionality. The weakness is identified as CWE‑862. The result can compromise the confidentiality, integrity, or availability of the site by letting a Subscriber perform actions that are normally reserved for higher‑privileged roles.
Affected Systems
The vulnerability affects WordPress sites that have installed any version of the Cyr to Lat reloaded – transliteration of links and file names plugin up to and including 1.3.3. The plugin is an individual WordPress plugin, so any site running these versions is exposed. No additional operating system or platform details are provided.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity. EPSS shows less than 1% probability of exploitation, and the vulnerability is not listed in CISA KEV. The likely attack vector is through legitimate plugin use by an authenticated Subscriber; the flaw is tied to role checks within the plugin code. The potential impact is limited to the scope of actions that the plugin exposes beyond normal Subscriber permissions, with low exploitation likelihood based on the given metrics.
OpenCVE Enrichment