Impact
The vulnerability is a missing authorization check in the Murali Push Notification for Post and BuddyPress plugin, allowing an attacker who can reach the plugin settings to change those settings. This flaw can alter push notification behavior and compromise the integrity of the site’s notification configuration. The weakness is classified as CWE‑862 Unauthorized Access.
Affected Systems
Murali:Push Notification for Post and BuddyPress, a WordPress plugin. All installations with a version number of 2.11 or earlier are vulnerable, as the issue exists from n/a through <= 2.11.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate impact, while the EPSS score of < 1% signals a very low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The attack vector is likely through the WordPress administrative interface, where an attacker with administrative privileges or implicit access to the plugin settings could modify them via the authorization bypass. Overall, the risk is moderate, but the potential for widespread configuration changes warrants prompt attention.
OpenCVE Enrichment
EUVD