Impact
A missing authorization flaw in the Dor Zuberi Slack Notifications by dorzki WordPress plugin allows an attacker to access and use the plugin’s configuration page without legitimate credentials. The vulnerability can be leveraged to modify notification settings, potentially enabling arbitrary messages to be posted to Slack channels. The weakness is classified as missing authorization (CWE‑862).
Affected Systems
WordPress sites running the Dor Zuberi Slack Notifications by dorzki plugin at version 2.0.7 or earlier are affected. No specific WordPress core or PHP version constraints are listed; the issue exists across all installations with the vulnerable plugin.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity impact. The EPSS score is below 1 %, suggesting low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw by accessing the plugin’s settings page through the web interface, bypassing expected user‑level restrictions. Relying on standard web authentication, the attacker does not need elevated privileges but must send requests to the plugin’s endpoints, which are currently unprotected by proper authorization checks.
OpenCVE Enrichment
EUVD