Impact
Missing Authorization vulnerability (CWE-862) in NotFound Bridge Core plugin allows an attacker to access plugin functionality that should be restricted. The issue is formally described as a broken access control flaw.
Affected Systems
WordPress Bridge Core plugin versions up to and including 3.3, released by NotFound, are affected. Any instance of the plugin at or below 3.3 is vulnerable; versions 3.3.1 and newer are reported to have the issue fixed.
Risk and Exploitability
The CVSS score of 4.3 indicates medium severity, while the EPSS score of less than 1% implies a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalogue. Based on the description, it is inferred that the exploit likely involves sending a web request to a protected endpoint without requiring special authentication, so a remote attacker with access to the site could potentially abuse it. No specific prerequisites are mentioned, which suggests that the attack can be performed by unauthenticated users.
OpenCVE Enrichment
EUVD