Impact
The StaticPress plugin by wokamoto for WordPress contains a missing authorization flaw that allows unauthorized users to access protected functionality and potentially alter or delete content. This vulnerability, classified as CWE‑862, enables an attacker to bypass authentication controls, leading to data integrity and confidentiality compromises. No remote code execution or denial of service is indicated by the description.
Affected Systems
All released versions of the StaticPress plugin by wokamoto, from n/a through <= 0.4.5, are affected, as noted by the vendor’s own guidance. The issue applies universally across all installations that have not upgraded beyond the stated limit.
Risk and Exploitability
The CVSS score of 4.3 reflects moderate severity, and the EPSS score of less than 1% indicates a low likelihood of exploitation in the wild. The vulnerability is not currently listed in the CISA KEV catalog. Based on the description, the likely attack vector involves sending crafted HTTP(S) requests to the plugin’s exposed endpoints, potentially without prior authentication. Given the modest severity and low exploitation probability, the risk is moderate but should be mitigated promptly.
OpenCVE Enrichment
EUVD