Impact
The vulnerability is a missing authorization flaw in the Blair Williams Shortlinks by Pretty Links WordPress plugin. Incorrectly configured access control levels allow users without proper privileges to perform actions that should be restricted. This can expose sensitive shortlink data and potentially enable further exploitation within the WordPress environment. Based on the description, it is inferred that attackers could gain unauthorized access to shortlink data.
Affected Systems
The vulnerability affects the Shortlinks by Pretty Links plugin for WordPress, developed by Blair Williams. Versions from undefined initial releases up to and including 3.6.15 are impacted.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity. The EPSS score of less than 1% suggests a low likelihood of exploitation at present, and the issue is not listed in the CISA KEV catalog. The likely attack vector is through the WordPress administration interface where the plugin manages shortlinks, allowing an attacker with access to the site’s frontend or backend to abuse the broken access control to modify or retrieve shortlink information.
OpenCVE Enrichment
EUVD