Impact
The No Spam At All plugin has a missing authorization flaw that permits users who should not have administrative permissions to alter security settings or other configuration options. This breach of access control can lead to unauthorized changes to the plugin’s behavior or exposure of sensitive data managed by the plugin. The weakness is classified as CWE‑862, highlighting a direct violation of defined privilege boundaries.
Affected Systems
WordPress sites that have installed the De paragon No Spam At All plugin version 1.3 or older are affected. The issue persists from the earliest available version up to and including 1.3, and is present on any site that has not upgraded beyond that release.
Risk and Exploitability
The CVSS score of 5.4 indicates a medium severity vulnerability. The EPSS score of less than 1% suggests that exploitation is unlikely at present, and the vulnerability is not listed in the CISA KEV catalog. The most plausible attack vector relies on web requests to the plugin’s configuration interface, most likely from an authenticated but insufficiently privileged account or through manual manipulation of URLs. Detection and exploitation would require knowledge of the specific plugin endpoints and an ability to authenticiate to the site.
OpenCVE Enrichment
EUVD