Impact
The vulnerability is a broken access control flaw affecting IMPress for IDX Broker version 3.3.0 and earlier. A subscriber role can exploit this issue to perform actions or access information that should be restricted, undermining the confidentiality of sensitive data handled by the plugin.
Affected Systems
WordPress sites that use the IMPress for IDX Broker plugin from IDX Broker, specifically versions up to 3.3.0.
Risk and Exploitability
The CVSS score is 6.3, indicating moderate severity. An EPSS score is not available, suggesting the exploitation probability cannot be quantified, and the vulnerability is not listed in CISA's KEV catalog. Likely attackers would need an authenticated subscriber session, and the flaw can be leveraged through the normal web interface of the plugin.
OpenCVE Enrichment