Impact
The Hive Support plugin version 1.2.5 and earlier suffers from a broken access control flaw that allows users to invoke plugin functions without proper authorization checks. This flaw can expose or alter site data that should be protected behind explicit permissions, effectively undermining the integrity and confidentiality of the application. The weakness is a classic example of CWE‑862, where access controls are insufficient.
Affected Systems
The vulnerability affects the WordPress Hive Support plugin, developed by Hive Support, for all releases up through 1.2.5. WordPress sites that have installed or activated any version of Hive Support from the earliest to 1.2.5 are potentially impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score of less than 1% suggests exploitation is unlikely at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector appears to be crafted HTTP requests to the plugin’s public endpoints; this inference is based on the description that the plugin exposes functionality without proper authorization checks, implying that even unauthenticated visitors or low‑privileged users could trigger the exposed functionality.
OpenCVE Enrichment
EUVD