Impact
The Just Writing Statistics plugin for WordPress contains a missing authorization flaw that allows attackers to exploit incorrectly configured access control levels. This weakness, identified as CWE‑862, permits unauthorized users to perform actions or read data that should be restricted, potentially exposing sensitive content or configuration settings. The CVSS score of 4.3 indicates a moderate risk associated with this flaw.
Affected Systems
The vulnerability affects all versions of Greg Ross's Just Writing Statistics plugin up through 5.3. Users running any of the listed versions are susceptible if the plugin is enabled on a WordPress site. No other plugins or versions are impacted by the current description.
Risk and Exploitability
The EPSS score of less than 1% suggests a low probability of seeing exploitation in the wild, and the issue is not listed in the CISA KEV catalog. Nonetheless, the flaw can be leveraged over the web, using the plugin’s public interface, especially if the site’s user roles lack proper restrictions. Administrators should treat this as a medium risk until the plugin is updated.
OpenCVE Enrichment
EUVD