Impact
The vulnerability is a missing authorization flaw that arises from incorrectly configured access control security levels within the WP Rocket plugin. An attacker can leverage this weakness to bypass proper authorization checks and gain unauthorized access to privileged functionality exposed by the plugin. The impact is the acquisition of access that should be limited to users with specific roles, potentially allowing configuration changes or sensitive data exposure. The weakness is classified as CWE‑862.
Affected Systems
The affected product is the WP Rocket WordPress plugin, developed by WP Media. Versions earlier than 3.23.5 are vulnerable; any deployment using these versions is impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. Because the EPSS score is not available, the exploitation likelihood cannot be quantified, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be remote, requiring access to a WordPress instance where the WP Rocket plugin is installed and the attacker can send requests that exercise the privileged endpoints.
OpenCVE Enrichment