Impact
The vulnerability is a missing authorization flaw that allows arbitrary deletion of content. An attacker who can exploit this flaw can remove posts or other WordPress content created through the plugin, thereby impacting data integrity and availability. The weakness is classified as CWE-862: Missing Authorization.
Affected Systems
The issue affects the WordPress plugin trusted as "enituretechnology LTL Freight Quotes – Worldwide Express Edition" in all releases up to and including 5.0.20. Sites using these plugin versions are at risk.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate risk, and the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The flaw is not listed in CISA KEV. Based on the description, it is inferred that the missing authorization check allows an attacker with sufficient access to the plugin’s administrative level to send requests that trigger content deletion, even if general WordPress access controls are in place. Thus the attack vector is likely achievable through the plugin’s admin interface or exposed endpoints without additional privileged credentials.
OpenCVE Enrichment
EUVD