Impact
The Pin Generator plugin for WordPress contains a missing authorization flaw that allows users to exploit incorrectly configured access control levels. Attackers can use the plugin’s endpoints to obtain or modify data without proper authentication. The weakness is captured by CWE‑862 – Missing Authorization. The impact is the potential disclosure of confidential information or unauthorized data alteration within the WordPress site.
Affected Systems
This vulnerability affects Oliver Boyers Pin Generator, a WordPress plugin, for all releases up to and including version 2.0.0. No versions beyond 2.0.0 are listed as impacted.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity. The EPSS score of <1% suggests a low probability of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. Likely attack vectors involve sending crafted requests to the plugin’s publicly reachable URLs when the site is accessible over the internet. Conditions for exploitation appear to be limited to an external attacker who can reach the WordPress instance and does not require privileged credentials.
OpenCVE Enrichment
EUVD