Impact
The vulnerability involves a missing Authorization check in the PAPERCITE plugin for WordPress. Because the plugin does not enforce proper access control, an attacker could potentially manipulate plugin functionality or data that should be restricted to privileged users, thereby compromising the integrity of the site content and potentially exposing sensitive information through the plugin interface. The weakness is identified as CWE-862, indicating Incorrect Authorization.
Affected Systems
This issue affects the WordPress PAPERCITE plugin, version 0.5.18 and earlier, from the first release onward. Administrators of WordPress sites using any of these versions should verify the installed plugin version and upgrade if necessary.
Risk and Exploitability
The CVSS score of 5.4 suggests moderate severity. The EPSS score of less than 1% indicates a very low but non-zero probability of exploitation at the time of analysis. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote, as the plugin is exposed through the web interface of a WordPress site; however, the exact path is inferred from the nature of the vulnerability and is not explicitly stated in the provided description.
OpenCVE Enrichment
EUVD