Impact
A missing authorization flaw in ValvePress Pinterest Automatic Pin allows an attacker to exploit incorrectly configured access control settings without proper checks. Because the plugin fails to enforce the intended security levels, users or processes that should be restricted could potentially trigger plugin functionality they are not permitted to use, exposing the site to unauthorized modifications or misuse of the plugin’s features.
Affected Systems
WordPress sites running ValvePress Pinterest Automatic Pin plugin versions up through and including 4.19.0 are affected. No specific sub‑version is required beyond the upper bound of 4.19.0.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity, while the EPSS under 1% suggests a very low likelihood that attackers currently target this flaw. The vulnerability is not listed in the CISA KEV catalog. Although the exact attack vector is not detailed, the description infers that the flaw can be leveraged through the plugin’s configuration interface or exposed endpoints by users who can reach them, potentially allowing any site user with those access rights to perform actions beyond their intended scope.
OpenCVE Enrichment
EUVD