Impact
The vulnerability is a broken access control flaw present in the WordPress Social Boost plugin versions up to 3.6.2. The flaw allows users with subscriber-level credentials to perform actions normally restricted to higher‑privilege roles, enabling the modification or deletion of plugin data and settings. The impact is confined to the Social Boost plugin itself and its configuration, potentially altering how the plugin behaves and interacts with the WordPress site.
Affected Systems
WordPress sites that have the Social Boost plugin from Apps Mav installed, with version 3.6.2 or earlier, are vulnerable. Only the plugin component is affected; the core WordPress installation remains unaffected unless the plugin is engaged in processing or storing sensitive information.
Risk and Exploitability
The CVSS score of 7.6 indicates high risk. EPSS data is unavailable and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be authenticated, as the flaw requires a subscriber account to exploit. Once authenticated, the attacker can bypass normal role checks and alter plugin data, degrading site reliability or compromising the plugin's intended functionality.
OpenCVE Enrichment