Impact
The vulnerability is a missing authorization flaw in the M.Code Url Rewrite Analyzer plugin for WordPress, identified by CWE-862. An attacker can exploit incorrectly configured access control security levels to bypass authentication checks and gain access to functions that should be restricted to privileged users, potentially allowing modification of rewrite rules or other sensitive settings.
Affected Systems
The affected component is the M.Code Url Rewrite Analyzer plugin for WordPress. Versions from its inception through 1.3.3 are vulnerable. Any WordPress site that has this plugin installed in one of these versions is subject to the exploitation risk. No specific operating system or PHP version is mentioned.
Risk and Exploitability
With a CVSS score of 4.3 the vulnerability carries moderate severity. The EPSS score of less than 1% indicates a low probability of exploitation in the current environment, and it is not listed in the CISA KEV catalog. Based on the description the likely attack vector involves sending crafted HTTP requests to the plugin’s admin endpoints that lack proper authorization checks, allowing an attacker to perform privileged actions without credentials.
OpenCVE Enrichment
EUVD