Impact
This vulnerability allows an authorized user with only subscriber-level access to bypass role checks in WordPress Fluent Support and access or modify functionality reserved for privileged roles. The result is a scoping of ownership that raises the likelihood of privilege escalation or data exposure. The weakness directly correlates with CWE-862, an access control deficiency that undermines confidentiality, integrity, and potentially availability within the plugin's scope.
Affected Systems
The issue impacts the WPManageNinja Fluent Support plugin versions 2.3.2 and older. Users running these or earlier builds are exposed until they upgrade to 2.4.0 or a later release that patches the control flow logic.
Risk and Exploitability
The CVSS score of 5.4 denotes medium severity, and there is no EPSS data available, so exploitation likelihood is indeterminate. The vulnerability is not listed in CISA KEV, which suggests no active exploit evidence yet. Attackers likely leverage remote access through the web interface, submitting crafted requests to the plugin's endpoints to defeat authorization checks. Given the medium CVSS and absence of exploitation data, the risk is moderate but should be mitigated promptly to prevent potential escalation.
OpenCVE Enrichment