Impact
A missing authorization check in the WordPress fluXtore plugin permits an attacker to invoke privileged plugin functions that should be restricted to authenticated users. Classified as CWE‑862, the flaw can lead to unauthorized disclosure, modification, or deletion of data managed by the plugin, thereby compromising the confidentiality, integrity, or availability of the site content.
Affected Systems
WordPress installations that have the fluXtore plugin version 1.6.0 or earlier, distributed by amazewp, are vulnerable. Any instance of the plugin at these versions, regardless of other plugins or themes, is affected; newer releases are immune.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1 % suggests a low current exploitation likelihood. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is via the WordPress web interface, where an external attacker can send HTTP requests to the plugin’s endpoints to exploit the authorization bypass. It is inferred that no special credentials are required, but the vendor does not explicitly state this, so the need for authenticated access remains uncertain.
OpenCVE Enrichment
EUVD