Description
Missing Authorization vulnerability in Bowo Variable Inspector variable-inspector allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Variable Inspector: from n/a through <= 2.6.3.
Published: 2025-04-04
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Variable Inspector plugin for WordPress contains a missing authorization flaw that allows attackers to exploit incorrectly configured access control levels. This broken access control can enable unauthorized users to read, modify, or delete settings or data that should be restricted, leading to possible data exposure or tampering. The vulnerability is specific to the Variable Inspector plugin version 2.6.3 and earlier; any installation of these versions is potentially vulnerable. All WordPress sites employing the affected plugin are at risk unless a newer version is in use. The CVSS score of 4.3 reflects a moderate severity, and the EPSS score of less than 1% indicates a very low likelihood of exploitation as of the current data. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves an external attacker accessing the public WordPress site and sending crafted requests to the plugin’s endpoints that bypass the missing authorization checks. Successful exploitation does not require elevated privileges beyond access to the site, making the risk moderate.

Affected Systems

The Bowo Variable Inspector plugin for WordPress, versions 2.6.3 and earlier, are affected. All WordPress sites running any of these versions of the plugin have the vulnerability.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity because the missing authorization allows attackers to access plugin settings and data that should be restricted. The EPSS score of less than 1% points to a low current exploitation probability, but the vulnerability still exists on unpatched WordPress installations. The plugin is not listed in CISA’s KEV catalog, meaning no widespread exploitation has been reported. Attackers can target the public WordPress site and send crafted requests to the plugin’s endpoints, bypassing access controls without needing administrative credentials, and thereby read or modify configuration values.

Generated by OpenCVE AI on May 2, 2026 at 02:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Variable Inspector plugin to a version newer than 2.6.3 to remove the missing authorization flaw.
  • If an upgrade is not immediately possible, disable or uninstall the plugin from the WordPress installation to eliminate the vulnerable functionality.
  • Verify that WordPress user roles and capabilities are correctly configured, applying the principle of least privilege to any remaining plugins and core features.

Generated by OpenCVE AI on May 2, 2026 at 02:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-9806 Missing Authorization vulnerability in Bowo Variable Inspector allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Variable Inspector: from n/a through 2.6.3.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Bowo Variable Inspector allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Variable Inspector: from n/a through 2.6.3. Missing Authorization vulnerability in Bowo Variable Inspector variable-inspector allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Variable Inspector: from n/a through <= 2.6.3.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Fri, 04 Apr 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Bowo Variable Inspector allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Variable Inspector: from n/a through 2.6.3.
Title WordPress Variable Inspector plugin <= 2.6.3 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:19.670Z

Reserved: 2025-04-04T10:01:50.054Z

Link: CVE-2025-32229

cve-icon Vulnrichment

Updated: 2025-04-04T19:52:38.784Z

cve-icon NVD

Status : Deferred

Published: 2025-04-04T16:15:32.040

Modified: 2026-04-23T15:28:47.713

Link: CVE-2025-32229

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T02:30:25Z

Weaknesses