Impact
The vulnerability in AnsPress 4.4.4 allows a subscriber or low‑privilege user to bypass the plugin’s access controls and perform actions reserved for higher‑privilege roles. This can lead to unauthorized modification or deletion of questions, answers, or site content, compromising the integrity of the site’s knowledge base.
Affected Systems
The flaw affects the AnsPress – Question and answer plugin version 4.4.4, which is distributed by lattepress. No other versions or products are listed as vulnerable.
Risk and Exploitability
With a CVSS score of 7.1 the issue is considered high severity, but the EPSS score is not available and the vulnerability is not listed in CISA KEV. Attackers can exploit the flaw by authenticating as a normal subscriber and accessing the plugin’s internal endpoints, thereby elevating their privileges and altering site content. The CWE indicates a broken authorization weakness.
OpenCVE Enrichment