Impact
The Vulnerability is a Missing Authorization flaw in the WordPress Debug Tool plugin, allowing generic users to access debug features that are meant to be restricted. This flaw aligns with CWE-862 and can lead to unauthorized data access or configuration exposure, impacting confidentiality and potentially enabling further attacks through the accessed information.
Affected Systems
WordPress Debug Tool plugin by Eugen Bobrowski, affected versions up to and including 2.2. The vulnerability applies to any installation of the plugin before and through version 2.2, regardless of other WordPress components.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. The EPSS score of less than 1% suggests low but non-zero exploitation likelihood, and the vulnerability is not listed in CISA KEV. The likely attack vector is over the web interface, where an attacker can exploit the plugin’s insufficient access checks to retrieve debug information.
OpenCVE Enrichment
EUVD