Impact
Missing Authorization within the Smart Hashtags [#hashtagger] plugin allows an attacker who reaches the plugin’s administrative interface to perform functions beyond their role, such as altering hashtag mappings. The CWE‑862 classification indicates that there is no remote code execution or direct data exfiltration; the primary consequence is the corruption or manipulation of site content. The likely attack vector is remote via HTTP requests to the plugin’s administrative functionality, though this is inferred from the description and not explicitly stated.
Affected Systems
Peter Raschendorfer’s Smart Hashtags [#hashtagger] WordPress plugin, versions through 7.2.3, is impacted. The description does not list a fixed version, so it is inferred that releases newer than 7.2.3 have addressed the flaw.
Risk and Exploitability
The CVSS base score of 4.3 indicates low severity, and the EPSS score of < 1% shows a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker would need either an authenticated session or an interface that fails to enforce proper authorization.
OpenCVE Enrichment
EUVD