Impact
Subscriber users in Leyka plugin versions 3.32.3 and earlier can be authenticated incorrectly, enabling an attacker to obtain access that should be denied. The flaw is an authentication failure flaw and is classified as CWE‑288. This could allow unauthorized users to view or manage subscription data, potentially exposing personal information or enabling further attacks.
Affected Systems
The vulnerability is limited to the Leyka donation plugin for WordPress sold by VaultDweller, affecting all installations running version 3.32.3 or earlier. No other WordPress plugins or core versions are impacted directly.
Risk and Exploitability
The CVSS score of 7.6 indicates high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been widely exploited. Based on the description, the attack vector is most likely an authenticated application‑level vulnerability within the plugin; an attacker with the ability to submit crafted requests could bypass normal authentication checks and gain subscriber privileges.
OpenCVE Enrichment