Impact
The Bertha AI WordPress plugin suffers from a Missing Authorization flaw that allows attackers to delete content arbitrarily. This vulnerability can result in the unintended removal of posts, pages, media, or other content, causing data loss and potential disruption to site operation.
Affected Systems
WordPress sites using the Bertha AI – Andrew Palmer plugin version 1.12.10.2 or earlier are vulnerable. No additional version details are provided.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity. The EPSS score is below 1%, suggesting low but non‑zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Exploitation likely requires authenticated access with sufficient privileges, but misconfigured access controls can allow unauthenticated users to trigger delete actions.
OpenCVE Enrichment
EUVD