Impact
The vulnerability is a missing authorization flaw that permits deletion of content. An attacker could delete posts, pages, or other pieces of content without proper privilege checks. This weakness is classified as CWE‑862 and results in an integrity breach, potentially disrupting site information.
Affected Systems
The flaw affects the Minterpress plugin for WordPress from vendors blokhauswp. Versions through 1.0.5 are impacted. No specific sub-versions are listed, so all releases up to and including 1.0.5 should be considered vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score is below 1 %, suggesting a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to access the plugin’s deletion functionality, likely via a web request. Since the flaw involves insufficient ACL checks, an authenticated user with any WordPress role could potentially delete content if the plugin does not enforce proper role validation.
OpenCVE Enrichment
EUVD