Impact
The Search Exclude plugin for WordPress contains a missing capability check in its REST API endpoint get_rest_permission. This flaw allows any unauthenticated user to send a request that changes the plugin’s configuration, thereby excluding content from search results. The primary impact is an unauthenticated authorization bypass that can alter site behaviour and potentially hide important posts or pages, affecting the integrity and availability of content discoverability.
Affected Systems
The vulnerability affects the quadlayers Search Exclude plugin for WordPress versions 2.4.9 and earlier.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score of less than 1% suggests exploitation likelihood is low, and the vulnerability is not currently listed in the CISA KEV catalog. Attackers can exploit the flaw by making unauthenticated HTTP requests to the plugin’s REST endpoint, bypassing any capability checks. Minimal conditions are required: the target must be a WordPress site running an affected version of the Search Exclude plugin.
OpenCVE Enrichment
EUVD