Impact
The vulnerability is a broken access control flaw in the WordPress Motors plugin that allows a user with subscriber privileges to gain unauthorized access to functionality normally reserved for higher‑level roles. An attacker who can log in with a subscriber account could potentially create, edit, delete, or otherwise manipulate content, thereby compromising the integrity of the site and potentially exposing confidential data. The weakness is classified as CWE‑862, indicating that the application does not enforce appropriate authorization checks.
Affected Systems
Infected sites are those running the WordPress Motors plugin version 1.4.113 or earlier, distributed by Stylemix. The affected component is the plugin’s internal handler for subscriber‑level requests; any WordPress installation that has not applied the 1.4.114 update is at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, with a potential impact on confidentiality, integrity, and availability if the plugin is exposed to the public web. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting that widespread exploitation has not yet been reported. Attackers would need to authenticate as a subscriber, making the vector likely a web‑application attack associated with normal user interaction on the site’s front‑end or administration pages. The lack of further exploitation prerequisites implies that the vulnerability can be leveraged by any authenticated subscriber once the plugin is present on a live site.
OpenCVE Enrichment