Impact
The vulnerability allows an attacker to bypass authentication controls and expose sensitive data by inserting it into externally accessible files or directories. This occurs because the Htaccess File Editor does not enforce proper access control, enabling the plugin to write to files that can be read by anyone with web access. The result can be unauthorized disclosure of configuration details or other sensitive information stored in the added files.
Affected Systems
WordPress plugin WP Chill Htaccess File Editor version 1.0.19 and any earlier releases are affected. Users running the plugin in any WordPress installation should verify the installed version and consider upgrading if a newer release is available.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact. The EPSS score of less than 1% suggests low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Attackers could exploit the weakness by accessing the plugin’s file editor interface without proper authentication, which the plugin mishandles due to its incorrect access‑control configuration. If the plugin is already publicly accessible, this can be done remotely without authentication.
OpenCVE Enrichment
EUVD