Impact
The vulnerability is a broken access control flaw present in WP Table Builder plugin versions 2.2.0 and earlier, classified as CWE-862. The CVE description indicates that a contributor-level user may be able to perform actions that should be restricted; however, the specific actions (such as viewing, modifying, or deleting table data) are not detailed in the description, so this is an inference.
Affected Systems
The affected product is the WordPress plugin WP Table Builder by the vendor WP Table Builder, specifically any installation using version 2.2.0 or earlier.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score is not available, suggesting that it is not currently a high‑volume exploit target. The vulnerability is not listed in the CISA KEV catalog. While the description does not reveal a detailed attack path, it is inferred that the likely attack vector could involve the public web interface of a WordPress site that hosts the plugin, where an attacker with contributor-level access might exploit the broken access control. Given the moderate score and limited exploitation data, the risk remains moderate but should still be addressed promptly.
OpenCVE Enrichment