Impact
Authentication is bypassed through an alternate path within the PrivateContent plugin, enabling an attacker to assume the identity of any user without credentials. The flaw maps to CWE-288, indicating improper authentication handling. An adversary could gain full access to a WordPress site, compromising confidentiality, integrity, and availability of all user data and site functions.
Affected Systems
The vulnerability affects the Aldo Latino PrivateContent plugin, all releases up to and including version 8.11.5. No earlier release is known to be vulnerable, and newer releases are presumed fixed.
Risk and Exploitability
The CVSS score of 9.8 reflects critical severity, but the EPSS score of less than 1% suggests that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog at this time. The likely attack vector is remote, via the web interface that offers an alternate authentication channel, and no authentication is required to exploit it.
OpenCVE Enrichment
EUVD