Impact
The vulnerability is a missing authorization flaw in the WordPress Wishlist plugin from redqteam, affecting all releases up to version 2.1.0. This flaw allows attackers to exploit incorrectly configured access control levels, granting them unauthorized access to the plugin’s configuration and potentially other protected resources. The weakness is classified as CWE‑862, indicating a broken access control mechanism.
Affected Systems
Affected software is the redqteam Wishlist plugin for WordPress, versions from unversioned releases up to and including 2.1.0. Users running any of these versions are potentially vulnerable.
Risk and Exploitability
The CVSS score of 4.3 categorizes this flaw as low severity, and the EPSS score of less than 1 % suggests a very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attackers would need to interact with the plugin’s exposed administrative endpoints, which are normally reachable from the web interface of a WordPress site. Because the flaw lies in the plugin itself, it can be exploited without additional system privileges, making the risk primarily a matter of unauthorized access rather than full system compromise.
OpenCVE Enrichment
EUVD