Impact
This vulnerability represents a broken access control that allows an attacker to invoke functionality within the iNET Webkit WordPress plugin that is not properly constrained by access control lists. The missing authorization flaw (CWE‑862) can result in an unprivileged user gaining access to privileged plugin features, potentially enabling further unauthorized actions within the WordPress site.
Affected Systems
All installations of the iNET Webkit plugin for WordPress with versions 1.2.2 or earlier are impacted. The affected product is the iNET Webkit plugin, distributed by iNET for use in WordPress sites.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests that exploitation is unlikely at this time. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote, via crafted HTTP requests sent to the plugin’s endpoints from any authenticated or anonymous user depending on the site configuration.
OpenCVE Enrichment
EUVD