Impact
Missing authorization in the Market Exporter plugin permits an attacker to exploit incorrect access control settings, allowing the extraction of site data that should be protected. This vulnerability falls under CWE‑862 and could lead to confidentiality breaches if sensitive content is exported without proper permissions.
Affected Systems
WordPress sites using the Market Exporter plugin by Anton Vanyukov, versions up to and including 2.0.21; any WordPress installation that has not applied a newer release is susceptible.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, and the EPSS score of less than 1% suggests a low likelihood of current exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker could exploit the plugin’s export functionality to retrieve data, though the specific endpoint is not documented. Because access is unchecked, even low‑privilege users could trigger the exploit, making the potential impact broad if the data is valuable.
OpenCVE Enrichment
EUVD