Impact
The CMB2 WordPress plugin before version 2.13.0 does not verify user capability for an AJAX action that creates or modifies WordPress options. A user with a Subscriber role can exploit this to create arbitrary options or corrupt existing ones, potentially breaking core site settings and taking the site offline. This vulnerability does not allow privilege escalation, as the stored value is not attacker-controlled.
Affected Systems
Any WordPress site that uses the CMB2 plugin with a version older than 2.13.0 and has at least one oEmbed field declared by the plugin. The vulnerability is vendor‑specific to the CMB2 WordPress plugin.
Risk and Exploitability
The vulnerability is exploitable through the plugin’s oEmbed AJAX endpoint, a path likely reachable from any user who can access the site. The attack requires only a Subscriber level account, making the risk moderate. The EPSS score is not available and the vulnerability is not listed in CISA KEV, indicating limited published exploitation. However, because it can disrupt essential site functionality, administrators should treat it as a high-impact issue.
OpenCVE Enrichment