Impact
The Social Web Suite WordPress plugin version 4.1.12 and earlier exposes an endpoint that accepts requests without authentication. This endpoint can write to any plugin setting, including a shared secret that protects privileged functionality. An attacker who submits a crafted request can overwrite the secret and thereby gain control over the plugin’s privileged commands, effectively elevating privileges within the site.
Affected Systems
All installations of the Social Web Suite WordPress plugin with a version of 4.1.12 or earlier. The product is managed by the unknown social web suite vendor, and the vulnerability only applies to the plugin itself, not to WordPress core or other plugins.
Risk and Exploitability
Because the vulnerable endpoint is publicly accessible, exploitation does not require credentials or user interaction beyond sending a crafted request. The lack of an EPSS score or listing in the KEV catalog suggests that exploitation has not yet been observed in the wild, but the potential for remote privilege escalation remains significant. The CVSS score is not publicly disclosed, but the nature of the vulnerability—unauthenticated arbitrary write to internal configuration—indicates a high severity likelihood. Attackers could fully control the plugin, enabling further compromise of the site if the privileged commands include malicious code execution or data exfiltration.
OpenCVE Enrichment