Impact
The vulnerability is a missing authorization flaw within the Northern Beaches Websites IdeaPush plugin. It allows an attacker to perform privileged actions that should only be available to authorized users. The flaw is categorized under CWE-862, indicating improper access control. Developers cannot rely on the plugin’s default security levels to restrict sensitive functionality, exposing the plugin to potential misuse.
Affected Systems
Any installation of the IdeaPush plugin for WordPress versions 8.71 or earlier is affected. The issue applies broadly to all vendors that have deployed these versions, with the primary product being the Northern Beaches Websites IdeaPush plugin.
Risk and Exploitability
The CVSS score of 5.8 rates this vulnerability as moderate, and the EPSS score of less than 1% suggests a low probability of widespread exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw through the plugin’s web interface, likely without needing elevated credentials, by sending requests that bypass the missing authorization check. The attack is straightforward for anyone with network access to the site and a Reactocing user session.
OpenCVE Enrichment
EUVD