Impact
Missing Authorization vulnerability in OLIVESYSTEM 診断ジェネレータ作成プラグイン os-diagnosis-generator allows accessing functionality that is not properly constrained by access control lists. The flaw means that an attacker could invoke privileged functions within the plugin without the required role or permission. Based on the description, it is inferred that unauthorized users could access features intended for authorized personnel, potentially exposing sensitive diagnostics or enabling tampering with plugin settings.
Affected Systems
The affected product is OLIVESYSTEM 診断ジェネレータ作成プラグイン (OS Diagnosis Generator) for WordPress, with all versions up to and including 1.4.16 identified as vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity level, while the EPSS score of less than 1% suggests a very low likelihood of exploitation at the time of this analysis. This vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote via the WordPress site, exploiting the plugin's lack of proper access controls, though this is inferred from the nature of the flaw rather than specified in the advisory.
OpenCVE Enrichment
EUVD