Impact
The WP Component WordPress plugin up to version 2.2.4 fails to enforce capability or nonce checks on one of its actions. This is a CWE-269 vulnerability, representing improper privilege management. The plugin accepts both the option name and value from the request, allowing an unauthenticated user to modify any site option. On a standalone site this can be leveraged to enable user registration with a full site takeover.
Affected Systems
Any WordPress site running the WP Component plugin version 2.2.4 or earlier. The vulnerability is vendor‑agnostic beyond the plugin and affects all sites that have installed the plugin.
Risk and Exploitability
The CVSS score is 9.8, reflecting a high‑severity remote vulnerability. The EPSS score is < 1% and the vulnerability is not listed in CISA KEV. Lack of authentication checks indicates a high potential to gain administrator privileges. An attacker with web access can submit a crafted request to overwrite critical options. Because the exploit requires no credentials, the attack can be performed from any internet‑connected client, enabling full site takeover on single‑site installations.
OpenCVE Enrichment