Impact
The WordPress EPROLO Dropshipping plugin versions up to 2.4.2 contain an unauthenticated broken access‑control flaw identified as CWE‑862. An attacker can send crafted requests to the plugin’s endpoints without authenticating and gain administrative privileges, potentially modifying configuration, injecting content, or altering the dropshipping workflow. This loss of authorization can compromise site integrity and data.
Affected Systems
The vulnerability affects the EPROLO Dropshipping plugin from vendor paulepro2019, specifically all releases dated 2.4.2 or earlier. WordPress sites that have installed any of these versions are vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, but the lack of these metrics does not reduce the risk posed by an unauthenticated flaw. The attack vector is inferred to be remote over the network; an attacker only needs to target the plugin’s endpoints, bypassing any login checks. Consequently, any publicly accessible WordPress installation with the vulnerable plugin is at risk of privilege escalation and can be exploited without prior authentication.
OpenCVE Enrichment