Impact
The Unify plugin for WordPress fails to enforce a capability check on the init action in all releases up to and including 3.4.9, allowing an unauthenticated user to specify the unify_plugin_downgrade parameter and delete arbitrary plugin options. This missing authorization flaw (CWE‑862) can compromise the configuration and stability of the site, potentially leading to service disruption or defacement.
Affected Systems
This issue affects any WordPress site running the Unify plugin version 3.4.9 or earlier, as distributed by CodeClouds. No other products or versions are listed as impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not included in CISA KEV. Attackers would need only to reach a public endpoint on the target WordPress installation and craft an HTTP request containing the unify_plugin_downgrade parameter; the absence of user authentication makes the attack vector straightforward but requires the site to be reachable.
OpenCVE Enrichment