Impact
Checkbox plugin misses a capability check on the AJAX endpoint "wp_ajax_nopriv_checkbox_clean_log", letting attackers clear log files without authentication. This results in the loss of audit trail data, which can obscure evidence in investigations and hinder security monitoring. The flaw is a missing authorization weakness classified as CWE‑862.
Affected Systems
Bandido’s Checkbox plugin for WordPress, all releases up to and including 2.8.10, is affected. Any WordPress site that has the plugin installed and active will be vulnerable unless the plugin is upgraded beyond 2.8.10.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and an EPSS score of less than 1% suggests exploitation is unlikely but not impossible. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit it by issuing an unauthenticated AJAX request to the public endpoint, requiring only a web‑connected WordPress installation with the plugin active. No user privileges or complex prerequisites are needed for the exploit.
OpenCVE Enrichment