Impact
This vulnerability occurs in the WordPress Bricksforge plugin for versions 3.1.8.8 and earlier. It allows an authenticated user with the Subscriber role to elevate privileges and gain higher access levels within the WordPress installation. The weakness is a classic privileged flaw, classified as CWE-266, which results in unauthorized escalation of authority over site content and settings.
Affected Systems
The affected product is the Bricksforge plugin from the vendor Bricksforge, used within WordPress sites. The vulnerability is present in all releases up to and including version 3.1.8.8. No other products or versions are listed as affected.
Risk and Exploitability
The CVSS score of 9.8 indicates a severe risk. Exploitation does not require a separate vulnerability; an attacker only needs to authenticate as a subscriber and then trigger the flaw. The EPSS score is not available, so the likelihood cannot be quantified, but the lack of a KEV listing suggests no known active exploitation at the time of analysis. Given that the plugin is publicly downloadable, a determined attacker with subscriber access could potentially abuse the flaw to obtain administrative rights, compromising confidentiality, integrity, and availability of the site.
OpenCVE Enrichment