Impact
The flaw is a missing authorization check in the Adnan Analytify WordPress plugin, which allows an attacker to carry out actions normally limited to more privileged users. Because the plugin does not enforce proper access control, a user who can reach the plugin's management interface could potentially view or modify analytics data and dashboard settings that should be protected. This weakness is classified as CWE-862, indicating the potential for privilege escalation or unauthorized data exposure.
Affected Systems
WordPress installations running the Analytify plugin version 5.5.0 or earlier are affected. The plugin is distributed under the Adnan:Analytify name and can be found in the WordPress plugin repository. No specific minor or patch releases are listed as fixed, so any deployment of the plugin at or below 5.5.0 is at risk.
Risk and Exploitability
The CVSS score of 4.3 places the issue in the moderate range, but the EPSS score of less than 1% suggests that it is unlikely to be actively exploited in the wild. The vulnerability is not listed in the CISA KEV catalog, further indicating low active exploitation risk. An attacker would need to have network or software access to the WordPress site and would exploit the plugin's management endpoints, which are usually accessible only to authenticated users. If a site has weak or widely shared credentials, the risk increases, but no public exploitation details are known.
OpenCVE Enrichment
EUVD