Impact
The vulnerability is a broken access control flaw in the WordPress ReactPress plugin, permitting users with subscriber role to access or modify administrative functions or sensitive content through the plugin’s interface. Classified as CWE-862, the flaw arises because the system does not enforce proper authorization checks. An attacker who can act as a subscriber may read or alter protected data, leading to breaches of confidentiality and integrity and potentially affecting availability if critical operations are exposed.
Affected Systems
The affected product is the WordPress plugin ReactPress, developed by rockiger. Versions up to and including 3.4.0 are impacted. WordPress sites that have installed a vulnerable version of this plugin are at risk; any user who can assume a subscriber role may exploit the flaw.
Risk and Exploitability
The CVSS score of 6 indicates a moderate level of severity, and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is not provided, but the lack of publicly available exploits suggests low to moderate exploitation likelihood. The likely attack vector is web‑based, requiring an authenticated subscriber to interact with the plugin. The exploit does not appear to need additional conditions beyond legitimate subscriber access, making the risk noteworthy for any site that relies on this plugin for content management.
OpenCVE Enrichment