Impact
The plugin implements a delete‑post‑copies feature without enforcing proper authorization checks, creating a missing‑authorization flaw. An attacker who can reach the plugin’s deletion interface can delete content without permission, exposing the site to data loss and potential confidentiality breaches. The weakness corresponds to CWE‑862, a typical access‑control violation.
Affected Systems
WordPress sites running the etruel WP Delete Post Copies plugin through version 5.5 are affected. The vulnerability applies to all installations of this plugin up to, and including, version 5.5, regardless of the WordPress version.
Risk and Exploitability
The CVSS score of 5.4 classifies the vulnerability as moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The issue is not currently listed in the CISA KEV catalog. The exploitation path likely involves reaching the plugin’s deletion functionality, but it is not explicitly stated whether authentication or specific user privileges are required; this is inferred from the nature of the access‑control flaw.
OpenCVE Enrichment
EUVD