Impact
The Convert WebP & AVIF – Quicq WordPress plugin contains a missing capability check on the "wpqai_disconnect_quicq_afosto" AJAX endpoint, allowing authenticated users with Subscriber-level access or higher to trigger an operation that disconnects the Afosto service. This flaw permits attackers to alter the plugin’s configuration and modify key data, potentially disrupting the integration with Afosto and undermining site functionality.
Affected Systems
All installations of the Convert WebP & AVIF – Quicq plugin for WordPress with versions up to and including 2.0.0 are affected. The vulnerability exists in every WordPress site that has this plugin installed, regardless of other configuration settings.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate impact, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires authentication; a user with at least Subscriber privileges can invoke the unsecured AJAX endpoint, but no elevated privileges or network-level access are necessary. The primary consequence is unauthorized modification of plugin configuration rather than a full system compromise.
OpenCVE Enrichment