WordPress EMI Calculator Plugin Missing Authorization Vulnerability Allowing Access Control Bypass

Vulnerability

A missing authorization vulnerability has been identified in the WordPress EMI Calculator plugin, specifically in versions through 1.1. This vulnerability allows for exploitation of improperly configured access control security levels, potentially leading to unauthorized changes in settings.

Impact

Exploitation of this vulnerability could result in unauthorized changes to settings, allowing attackers to manipulate the plugin's configuration without proper authorization.

Remediation

Users of the WordPress EMI Calculator plugin are advised to update to version 1.1 or later, where this vulnerability has been addressed. For those unable to update immediately, a virtual patch is available through Patchstack to mitigate the issue until an official update can be applied.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
7.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.