Impact
This vulnerability is a missing authorization flaw that allows attackers to bypass configured access control settings. Because of the lack of proper checks, an attacker could gain access to restricted functionality within the plugin, potentially exposing sensitive data or enabling further compromise. The weakness is classified under CWE‑862, which covers missing authorization.
Affected Systems
The affected product is the Accessibility Suite plugin from Ability, Inc for WordPress. Versions from the earliest available up to and including 4.19 are vulnerable. No specific sub‑versions are enumerated, so the entire range up to 4.19 should be considered at risk.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity. The EPSS score being less than 1% suggests a low probability of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. While the CVE description does not state an exact attack vector, the nature of the plugin and its web interface make it likely that exploitation would occur remotely via a web user's session or by an authenticated user with insufficient privileges.
OpenCVE Enrichment
EUVD