Impact
This vulnerability stems from a missing authorization check in the jidaikobo Dashi WordPress plugin, which allows attackers to access privileged functionality that should be restricted by access control lists. The flaw enables an unauthenticated or low‑privilege user to trigger operations that could alter or disclose sensitive data, representing a moderate severity flaw classified as CWE‑862.
Affected Systems
The vulnerability affects the Dashi plugin distributed by jidaikobo. Any installation of Dashi version 3.1.8 or earlier is impacted, as the Access Control issue exists through the end of that version series.
Risk and Exploitability
With a CVSS score of 5.8, the flaw represents moderate risk. The EPSS score of < 1 % indicates a low probability that this vulnerability will be exploited in the wild. It is not listed in the CISA Known Exploited Vulnerabilities catalog, and no exploit code has been publicly disclosed. The likely attack vector is remote via the web interface, where an attacker can invoke the vulnerable plugin functions without proper authentication.
OpenCVE Enrichment
EUVD