Impact
The vulnerability is a broken access control flaw that allows an unauthenticated or improperly authenticated user to exploit incorrectly configured security levels in the ValvePress Wordpress Auto Spinner plugin. An attacker could gain unauthorized access to plugin functions or modify content, leading to potential data tampering or other malicious activity.
Affected Systems
The impacted product is ValvePress Wordpress Auto Spinner, affecting all versions from the earliest available release through 3.25.0.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity, while the EPSS score of less than 1% shows a very low probability of exploitation at this time. The flaw arises from missing authorization checks, meaning the attack complexity is low and the likely attack vector is through the web interface of the plugin. The vulnerability is not listed in CISA’s KEV catalog, indicating no confirmed active exploits in the wild.
OpenCVE Enrichment
EUVD