Description
Missing Authorization vulnerability in Oliver Boyers Pin Generator pin-generator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Pin Generator: from n/a through <= 2.0.0.
Published: 2025-04-01
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Pin Generator plugin for WordPress contains a missing authorization flaw that allows users to exploit incorrectly configured access control levels. Attackers can use the plugin’s endpoints to obtain or modify data without proper authentication. The weakness is captured by CWE‑862 – Missing Authorization. The impact is the potential disclosure of confidential information or unauthorized data alteration within the WordPress site.

Affected Systems

This vulnerability affects Oliver Boyers Pin Generator, a WordPress plugin, for all releases up to and including version 2.0.0. No versions beyond 2.0.0 are listed as impacted.

Risk and Exploitability

The CVSS score of 5.4 indicates a moderate severity. The EPSS score of <1% suggests a low probability of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. Likely attack vectors involve sending crafted requests to the plugin’s publicly reachable URLs when the site is accessible over the internet. Conditions for exploitation appear to be limited to an external attacker who can reach the WordPress instance and does not require privileged credentials.

Generated by OpenCVE AI on May 1, 2026 at 02:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Pin Generator to a version newer than 2.0.0, using the official WordPress updater or the plugin’s download source.
  • If upgrading immediately is impractical, restrict the plugin’s pages and API endpoints to authenticated users by employing role‑based permissions or by adding access controls at the web‑server level.
  • Remove or disable any leftover files from older Pin Generator installations to ensure that the vulnerable code cannot be invoked after an upgrade.

Generated by OpenCVE AI on May 1, 2026 at 02:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-9244 Missing Authorization vulnerability in Oliver Boyers Pin Generator allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Pin Generator: from n/a through 2.0.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Oliver Boyers Pin Generator allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Pin Generator: from n/a through 2.0.0. Missing Authorization vulnerability in Oliver Boyers Pin Generator pin-generator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Pin Generator: from n/a through <= 2.0.0.
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


Tue, 01 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Apr 2025 15:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Oliver Boyers Pin Generator allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Pin Generator: from n/a through 2.0.0.
Title WordPress Pin Generator Plugin <= 2.0.0 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:12.898Z

Reserved: 2025-04-01T13:20:05.024Z

Link: CVE-2025-31791

cve-icon Vulnrichment

Updated: 2025-04-01T18:35:06.196Z

cve-icon NVD

Status : Deferred

Published: 2025-04-01T15:16:17.147

Modified: 2026-04-23T15:28:18.137

Link: CVE-2025-31791

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T02:15:06Z

Weaknesses