Impact
Apptivo Business Site CRM for WordPress has a missing‑authorization flaw that permits an attacker to delete content such as posts, pages, or other records. The weakness is a classic “Missing Authorization” issue (CWE‑862) where incorrect access controls allow a user without appropriate rights to trigger deletion operations. Loss of content can compromise data integrity, disrupt business processes, and erode customer trust.
Affected Systems
The vulnerability affects the Apptivo Business Site CRM WordPress plugin version 5.3 and all earlier releases. Administrators and developers using this plugin should verify whether their installation is at or below 5.3 and then plan an upgrade or mitigation accordingly.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, yet the EPSS score of less than 1% suggests that the probability of exploitation in the wild is currently very low, and the flaw is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is through a web‑based request to the plugin’s delete endpoint, potentially requiring authenticated access or exploit of improperly configured user roles. If an attacker can reach this endpoint, they can perform arbitrary deletions without further privileges.
OpenCVE Enrichment
EUVD