Impact
A missing authorization flaw in the jjtrabucco Goldstar plugin permits users to bypass configured access control levels and potentially access or modify content they should not see. The vulnerability is a classic example of CWE-862, where checks for proper permissions are omitted or incorrectly enforced. An attacker who can trigger the vulnerable functionality could read sensitive data or perform actions beyond their intended role.
Affected Systems
WordPress sites using the Goldstar plugin up to and including version 2.1.1 are affected. All installations of jjtrabucco Goldstar that have not been updated to a newer release are at risk.
Risk and Exploitability
The CVSS score of 4.3 indicates a low to moderate severity, and the EPSS of less than 1% shows a very low probability of real‑world exploitation. The vulnerability is not listed in CISA’s KEV catalog. Based on the plugin’s nature, the likely attack vector is a web request sent to the plugin’s endpoints, where an attacker can craft a request that exploits the missing authorization checks. No additional conditions such as remote code execution or privilege escalation beyond the application layer are described in the CVE data.
OpenCVE Enrichment
EUVD