Impact
The vulnerability is a missing authorization flaw in the Publitio WordPress plugin that allows attackers to bypass access controls and perform actions reserved for higher‑privileged users. This breach of access controls can lead to unauthorized data exposure or manipulation within the WordPress site, compromising the confidentiality and integrity of site content and user data. The weakness is identified as CWE‑862 (Broken Access Control).
Affected Systems
The affected software is the Publitio plugin for WordPress (publitio:Publitio). All installations running version 2.1.8 or earlier are vulnerable; the plugin versions prior to 2.1.8 have not been patched.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate risk, while the EPSS score of less than 1% suggests the likelihood of exploitation is very low. The vulnerability is not listed in CISA’s KEV catalog, further indicating it is not a high‑profile exploit. The attack vector is inferred to be remote via the web interface, as the flaw exists within a WordPress plugin that is exposed to authenticated or unauthenticated users, depending on the site’s configuration.
OpenCVE Enrichment
EUVD