Impact
The vulnerability is a missing authorization flaw that lets an attacker bypass the plugin’s built‑in access checks and invoke functions that are normally reserved for authenticated users. This deficiency is identified as CWE‑862, meaning that the enforcement of access control policies is absent. The flaw could allow unauthorized manipulation of the terms and conditions data that the plugin manages.
Affected Systems
Giannis Kipouros’s Terms & Conditions Per Product WordPress plugin versions 1.2.15 and earlier are affected. All releases listed up to and including 1.2.15 contain the missing authorization issue; no later versions are mentioned as vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity vulnerability. The EPSS score of < 1% suggests exploitation in the wild is unlikely. The vulnerability is not listed in the CISA KEV catalog, and no public exploit has been reported. The likely attack vector is inferred to be a web request to the plugin’s administrative interface or authorized user actions; to exploit the flaw the attacker may need basic authentication on the WordPress site, but the missing checks enable privilege escalation within the plugin’s scope.
OpenCVE Enrichment
EUVD