Impact
The vulnerability is a missing authorization flaw that allows users to access functionality that should be restricted by access control lists. An attacker who can trigger the affected routines could gain unauthorized privileges, read or manipulate data, or otherwise exploit the plugin’s restricted actions without proper permission. The impact is a breach of confidentiality, integrity, and potentially availability of the WordPress installation and the Etsy shop integration.
Affected Systems
The affected product is Embed360’s Embed and Integrate Etsy Shop for WordPress. All releases with a version number of 1.0.8 or earlier are vulnerable. No other vendors or product lines are impacted according to the CNA data.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk, and the EPSS score of less than 1% suggests low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a web-based application issue; an authenticated or even unauthenticated user with access to the WordPress site could exploit the broken ACL to misuse the plugin’s functionality. Since it involves broken access control, the exploitation requires compromise of the plugin’s internal boundaries rather than a network-level attack.
OpenCVE Enrichment
EUVD