Impact
The vulnerability is a Missing Authorization flaw that allows attackers to bypass access controls in the Sur.ly WordPress plugin. It stems from incorrectly configured security levels that fail to check user privileges before granting access to certain administrative functions. Attackers could exploit this to gain unauthorized access to configuration settings or data that should be restricted, potentially exposing sensitive site information. The weakness is identified as CWE-862: Broken Access Control.
Affected Systems
The flaw affects the Sur.ly plugin for WordPress distributed by surdotly. All released versions up to and including 3.0.3 are vulnerable. Versions earlier than those products may contain the same issue but the range is from the initial release (n/a) through <=3.0.3.
Risk and Exploitability
The CVSS base score of 4.3 reflects medium severity. The EPSS score of <1% indicates a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Likely the attack vector involves web requests to the plugin’s administrative interfaces in a WordPress installation. An attacker who obtains a valid session or can guess administrative URLs could exploit the missing authorization check to perform privileged actions. Given the medium severity and low exploitation probability, this risk should be monitored but addressed promptly by applying a patch or disabling the plugin.
OpenCVE Enrichment
EUVD