Impact
The vulnerability in the ContentMX Content Publisher plugin is a broken access control flaw that allows anyone with sufficient access to the WordPress site to bypass authorization checks. This flaw is identified by the missing authorization requirement and is classified as CWE-862. An attacker can potentially read, modify, or delete published content without proper permission, impacting the integrity and confidentiality of website data.
Affected Systems
This issue affects the ContentMX Content Publisher plugin for WordPress versions up to and including 1.0.6. The affected product is the ContentMX Content Publisher plugin distributed by ContentMX.
Risk and Exploitability
The CVSS score of 5.4 indicates a medium severity vulnerability, while the EPSS score of less than 1% suggests a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation would likely occur through a web interface or API endpoint used by the plugin, with potential impact limited to users who can reach the plugin’s functionality.
OpenCVE Enrichment
EUVD