Impact
Missing authorization in the Greek Multi Tool – Fix peralinks, accents, auto create menus and more plugin permits attackers to bypass intended access controls. The broken access control allows unauthorized users to perform actions such as creating, editing, or deleting menus and other privileged operations without proper authentication. This weakness can lead to unauthorized configuration changes, defacement, or further exploitation of the WordPress site.
Affected Systems
The vulnerability affects the WordPress plugin Greek Multi Tool – Fix peralinks, accents, auto create menus and more from any version through 2.3.1. The plugin is maintained by bigdrop.gr. WordPress sites that have this plugin installed, versions 2.3.1 and earlier, are impacted.
Risk and Exploitability
The CVSS score of 7.5 indicates a medium‑to‑high impact. The EPSS score of less than 1% suggests that widespread exploitation is unlikely at present, and the vulnerability is not listed in the CISA KEV catalog. Attackers can likely exploit the flaw via the web interface of the plugin, potentially without authentication, by sending specially crafted requests to privileged endpoints. Remote exploitation is possible if the WordPress site is publicly accessible and the plugin’s administrative features are exposed.
OpenCVE Enrichment
EUVD