Impact
A missing authorization check in the Acclectic Media Organizer plugin for WordPress allows an attacker to read or alter media organization data. The flaw is a broken access control weakness (CWE-862) that could let an individual view, modify, or delete files and configuration settings associated with the plugin.
Affected Systems
The vulnerability affects WordPress installations that have Acclectic Media Organizer version 1.4 or earlier, regardless of the WordPress core version. Site owners using any of these plugin versions are at risk if the plugin is accessible through the web interface.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity, while the EPSS score of less than 1% suggests a low historical exploitation likelihood. The flaw is not listed in CISA’s KEV catalog. Based on the description it appears that an attacker can exploit the missing access control by sending requests to the plugin’s endpoints via the web interface; authentication requirements are not explicitly stated, so both authenticated and unauthenticated users may be able to exploit it.
OpenCVE Enrichment
EUVD