Impact
The vulnerability in ClickWhale is a missing authorization flaw that allows a user who can authenticate to the WordPress site to access restricted actions or data within the plugin. This issue can enable the attacker to view, modify, or delete content or settings that should be protected, thereby threatening the confidentiality and integrity of site data. The flaw arises from incorrectly configured access‑control security levels within the plugin code.
Affected Systems
ClickWhale plugin versions up to and including 2.4.6 are affected; the issue exists from the earliest release through version 2.4.6 regardless of site configuration.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation at the time of this analysis. The vulnerability is not listed in CISA KEV. Based on the description, it is inferred that the flaw requires authenticated access; publicly available information does not indicate that it can be exploited from an unauthenticated context.
OpenCVE Enrichment
EUVD