Impact
The Publitio WordPress plugin contains a missing authorization flaw that lets attackers bypass the intended security checks. Through this flaw, malicious actors could access or alter content and settings managed by the plugin, representing a breach of confidentiality and integrity and fitting the CWE-862 category for improper authorization.
Affected Systems
WordPress installations running the Publitio plugin version 2.1.8 or earlier are affected. Any site that has deployed these plugin versions before remediation is at risk.
Risk and Exploitability
With a CVSS score of 4.3 the vulnerability is of moderate severity, and the EPSS score of less than 1% indicates a low probability of exploitation in the wild. The flaw is not listed in CISA KEV, so there is no evidence of large‑scale exploitation. The likely attack route involves an attacker invoking the plugin’s functionality without proper authorization, potentially through unauthenticated or low‑privilege user access, though the exact vector is not explicitly delineated in the description.
OpenCVE Enrichment
EUVD