Impact
The PuppyFW WordPress plugin up to version 0.4.4 lacks proper authorization on a REST route; it verifies the caller against a capability supplied in the request. This flaw (CWE-269) lets any authenticated user, including subscribers, add, modify, or delete arbitrary blog options, enabling them to elevate their privileges and potentially take full control of the site configuration.
Affected Systems
PuppyFW plugin versions 0.4.4 and earlier on WordPress installations.
Risk and Exploitability
With a CVSS score of 8.8, the vulnerability is considered high severity. The EPSS score of less than 1% indicates a very low likelihood of exploitation at present, and the issue is not listed in the CISA KEV catalogue. The attack vector is an authenticated, remote request to an unprotected REST endpoint. An attacker with subscriber-level access can exploit the flaw to modify site options, potentially granting themselves higher privileges or introducing malicious settings.
OpenCVE Enrichment