Impact
The vulnerability is a missing authorization flaw (CWE-862) that allows an attacker to access functionality that should be protected by access control lists. Because the vulnerability is tied to a logical flaw in the plugin's permission checks, an attacker can exploit it to read, modify, or delete ticket data that was intended for authenticated users only, potentially compromising data integrity and confidentiality.
Affected Systems
All installations of the WordPress plugin Joe Dolson:My Tickets, from n/a through version 2.0.9, run within the WordPress environment and provide ticket management features to site administrators and users.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity, while the EPSS score of less than 1% suggests that the likelihood of exploitation is low but not negligible. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be through the web interface of WordPress; an attacker with web access and potentially the ability to trigger the affected plugin functions could bypass required authorization checks to gain unauthorized actions over the ticket system.
OpenCVE Enrichment
EUVD