Impact
The vulnerability allows an unauthenticated user to elevate privileges within a WordPress site that uses the Authorizer plugin. By exploiting a missing authentication check in plugin code, an attacker can gain administrative rights. The weakness falls under CWE-266 and could be used to modify site content, install malware, or access sensitive data.
Affected Systems
The issue affects the WordPress Authorizer plugin (developed by Paul Ryan) in all versions up to and including 3.15.1. Any WordPress instance using this plugin version is potentially vulnerable.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated web request that triggers the privilege escalation code within the plugin, which means an attacker does not need credentials to exploit this flaw.
OpenCVE Enrichment