Impact
The vulnerability is a missing authorization flaw in the Magnigenie RestroPress WordPress plugin. An attacker can execute functions that should be protected by authentication, such as viewing, editing, or deleting restaurant reservations and menu items. This missing check can compromise confidentiality and integrity of critical business data, and could indirectly affect availability by enabling disruptive actions.
Affected Systems
Magnigenie RestroPress WordPress plugin on WordPress sites, affecting all releases from the first available version up to and including 3.2.8. The earliest release point is not documented in the CVE data, but any version at or below 3.2.8 is vulnerable.
Risk and Exploitability
The CVSS score of 4.3 places the flaw in the moderate range, while the EPSS score of less than 1% indicates a very low likelihood of exploitation at present. It is not listed in the CISA KEV catalog. The likely attack vector involves the plugin’s exposed WordPress REST API or other HTTP endpoints that allow administrative actions without verifying user privileges.
OpenCVE Enrichment
EUVD