Impact
The vulnerability is an unauthenticated Insecure Direct Object Reference flaw in WordPress Team plugin versions up to 6.0.0. An attacker can supply arbitrary object identifiers to read or modify data that the plugin manages, such as team member profiles or configurations. This compromises both the confidentiality and integrity of the plugin’s data. The weakness is a classic IDOR, classified as CWE-639.
Affected Systems
The affected product is the RadiusTheme:Team WordPress plugin. Versions 6.0.0 and older contain the flaw. The vendor recommends updating to at least version 6.0.1 to receive the fix.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and no EPSS data or KEV listing is available, suggesting that the vulnerability is known but not actively exploited at scale. The flaw can be triggered by any unauthenticated web request that targets the plugin’s endpoints, so any visitor to the site can potentially exploit it. The primary attack vector is a URL‑based request that manipulates object identifiers.
OpenCVE Enrichment