Impact
A flaw in the WC Lovers WCFM Membership plugin for WordPress allows a subscriber user to elevate their privileges. The vulnerability results from improper enforcement of role checks and can lead to an attacker gaining administrative access.
Affected Systems
The issue affects installations of the WC Lovers WCFM Membership plugin up to and including version 2.11.11. If a WordPress site uses this plugin and has subscriber accounts, it is potentially vulnerable. Sites running newer versions, such as 2.12.0 or later, are not affected.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity, and while an EPSS score is not available, the lack of data suggests a potential but unknown exploitation likelihood. The vulnerability is not currently listed in CISA’s KEV catalog. The likely attack vector is that an authenticated subscriber could trigger role assignment logic to elevate privileges; this exploits CWE‑266, an Improper Privilege Management flaw.
OpenCVE Enrichment