Impact
This vulnerability is a broken access control flaw identified in the WordPress Gratisfaction plugin versions 4.6.3 and earlier. The flaw allows an attacker to bypass normal subscriber restrictions and access restricted subscriber features or pages. The weakness is categorized as CWE-862, a type of incomplete authorization that can grant inappropriate privileges.
Affected Systems
The issue affects the Gratisfaction All‑In‑One Loyalty & Contest plugin for WordPress, specifically versions up to and including 4.6.3. Sites that use the plugin as a subscriber management component are at risk if the plugin remains unpatched.
Risk and Exploitability
With a CVSS score of 7.6, the vulnerability is considered high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that widespread exploitation has not yet been reported. Attackers would typically need the ability to craft requests to the plugin’s subscriber‑only endpoints, often via authenticated or unauthenticated access to the WordPress site. Once access control checks are bypassed, the attacker can perform privileged actions against the subscriber user base or the plugin’s protected data.
OpenCVE Enrichment