Impact
The WP‑Stateless plugin contains a flaw that allows a user with a lower‑level role to modify subscriber settings that should be restricted to administrators, because the plugin does not perform a proper authorization check when saving these settings. This weakness—Missing Authorization (CWE‑862)—can be leveraged by an attacker to change configuration values, potentially causing a loss of integrity in subscription data and enabling further attacks such as phishing or unauthorized access to content.
Affected Systems
This vulnerability affects the WordPress WP‑Stateless plugin version 4.4.1 and any earlier releases released by UDX Usability Dynamics. No other WordPress core components or third‑party plugins are directly impacted. The flaw exists in the plugin code and is fixed in version 4.4.2 and later.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity. Because the vulnerability only requires the presence of the plugin and no special user credentials, attackers can exploit it on any site that has the affected plugin installed and a non‑administrator account with subscriber access. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, but the high CVSS coupled with widespread WordPress adoption suggests a realistic exploitation probability.
OpenCVE Enrichment