As immediate action, update the affected plugin. If you're unable to do so, ask your hosting provider or web developer for help.
Users can access pages or perform actions they shouldn't be allowed to, like viewing other people's data.
CVSS score is a way to evaluate and rank reported vulnerabilities in a standardized and repeatable way but which is not ideal for WordPress.
This security issue has a low severity impact and is unlikely to be exploited.
Patchstack has issued a mitigation rule to block any attacks until an official patch becomes available, can be tested and be safely applied.
29 Nov, 2023