Impact
Missing authorization in the Agency Toolkit plugin allows attackers with lower privileges to access or modify protected resources, potentially leading to unauthorized data disclosure or modification. The weakness is a missing authorization check, identified as CWE‑862.
Affected Systems
The WordPress Agency Toolkit plugin (inspry:Agency Toolkit) from the earliest documented release through 1.0.24 is affected. WordPress sites running these versions are at risk.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score of less than 1% signals a very low likelihood of exploitation in the wild, and the vulnerability is not currently listed in the CISA KEV catalog. Based on the description, it is inferred that exploitation could involve an attacker with some level of authentication who submits requests to the plugin’s API or webpages that bypass the intended access controls, allowing unauthorized data access or modification.
OpenCVE Enrichment
EUVD