Impact
The vulnerability is a missing authorization flaw that allows attackers to exploit incorrectly configured access control security levels in the WordPress Rentsyst plugin. This broken access control can potentially let an attacker perform actions beyond the intended privileges, thus affecting the confidentiality, integrity, or availability of data handled by the plugin.
Affected Systems
The affected product is the WordPress Rentsyst plugin developed by DimaFreund. All releases from the earliest available version up through 2.1.2 are vulnerable. The plugin is installed on WordPress sites that have not yet upgraded to a patched version.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score is not available, so the likelihood of exploitation is uncertain, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the most likely attack vector is a web‑based request that targets the plugin’s endpoints. Attackers only need access to the site’s URL structure; no special privileges are required beyond what is normally available to anyone who can reach the WordPress installation.
OpenCVE Enrichment