Impact
The vulnerability is a missing authorization flaw in the Mobile App Canvas WordPress plugin up to version 3.8.2 that allows attackers to exploit incorrectly configured access control levels. This flaw is defined as CWE‑862 and can enable unauthorized viewing or manipulation of content that should be restricted to certain user roles, potentially exposing sensitive site data or compromising site integrity.
Affected Systems
The affected product is the Mobile App Canvas plugin developed by pietro, affecting all releases from the first available version through 3.8.2. Updating to a later release removes the flaw.
Risk and Exploitability
The CVSS score of 5.4 indicates a medium severity vulnerability, while the EPSS score of less than 1% suggests a low likelihood of being exploited in the wild. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that an attacker who can issue requests to the plugin’s endpoints may bypass proper access controls and access data beyond their permission level. No publicly available exploit code has been reported, and the low EPSS score further suggests limited exploitation risk at present.
OpenCVE Enrichment
EUVD