Impact
The vulnerability is a missing authorization flaw in the AutoWP plugin developed by Basar Ventures. It allows attackers to bypass intended access controls and exploit incorrectly configured security levels within the plugin. The weakness aligns with CWE‑862, meaning any entity that should be restricted can gain unauthorized access to privileged plugin functionality.
Affected Systems
All versions of the AutoWP plugin up to and including version 2.2.7 are affected. The plugin is distributed by Basar Ventures under the name AutoWP.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate impact, while the EPSS score of less than 1% shows a low probability that the vulnerability is widely exploited. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote through the WordPress site, where an attacker could interact with the plugin’s endpoints or features without possessing proper permissions. Exploitation requires that the vulnerability exists in the deployed plugin instance and that the plugin is accessible to the attacker. No additional exploitation prerequisites are documented in the provided data.
OpenCVE Enrichment
EUVD