Impact
The vulnerability is a missing authorization flaw in the Astra Security Suite plugin for WordPress, allowing attackers to exploit incorrectly configured access control levels. This flaw can let an unauthenticated or low‑privilege user read, modify, or delete content or perform other privileged operations that should be restricted. The weakness corresponds to CWE‑862.
Affected Systems
Affected components are the Astra Security Suite WordPress plugin developed by WebProtect.ai, specifically the getastra module. Versions from the original release through 0.2 are impacted, including any installations of the plugin with a version number of 0.2 or lower.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity risk, and the EPSS score of less than 1% suggests that observed exploitation is very unlikely. The vulnerability is not catalogued in the CISA KEV list. The likely attack vector is a remote attacker sending HTTP requests to the plugin’s exposed endpoints without proper authentication checks. Successful exploitation would allow unauthorized access to protected areas of the WordPress site.
OpenCVE Enrichment
EUVD