Impact
The Mark Posts WordPress plugin exhibits a missing authorization check that permits users to perform actions beyond the permissions intended for their role. This flaw, recorded as a broken access control vulnerability, can allow a compromised or low‑privileged account to modify, reorder, or delete posts and alter plugin settings. The impact is limited to integrity and potential availability of the site’s content, with no mention of remote code execution or denial of service.
Affected Systems
This issue affects all versions of the Mark Posts plugin from the earliest release through version 2.2.4, produced by flymke. Any WordPress site that hosts this plugin, regardless of its installation level, is potentially impacted.
Risk and Exploitability
The CVSS score of 5.4 categorizes the weakness as medium severity. An EPSS score of less than 1% indicates a low probability of exploitation at the time of analysis, and the flaw is not listed in CISA’s KEV catalog, suggesting no publicly known exploits. The vulnerability can be leveraged via the plugin’s configuration pages, typically by a user who has logged in and can reach the Mark Posts interface. The likely attack vector is a web request to the plugin’s administrative endpoints, bypassing intended role checks for non‑admin users. The absence of remedial solutions in public advisories implies that an unpatched site must handle the risk through updating or disabling the plugin.
OpenCVE Enrichment
EUVD