Impact
The Delete All Posts WordPress plugin suffers from a missing authorization flaw (CWE‑862) that lets an attacker exploit incorrectly configured access control security levels to trigger the delete‑all action. By doing so, the attacker can delete all posts from the site, resulting in substantial data loss and disrupting site functionality. This vulnerability does not provide code execution or other advanced capabilities, but it severely compromises content integrity.
Affected Systems
The vulnerability affects the WordPress plugin Delete All Posts released by mingocommerce, all versions up to and including 1.1.1.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, while the EPSS score below 1% suggests a low probability of current exploitation, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the effective attack surface is high because the plugin can likely be invoked via a web request; based on the description, it is inferred that any user with basic access could potentially trigger the deletion. Site administrators should treat this as a critical data‑loss risk until a fix is applied.
OpenCVE Enrichment
EUVD