Impact
This vulnerability is a missing authorization defect in the WordPress plugin Dariolee Netease Music. It permits an attacker to bypass normal access controls and potentially view or modify content that should be restricted to privileged users. The flaw arises from incorrectly configured access‑control security levels. The available CVSS metric is 4.3, indicating moderate severity. Because the description does not detail the exact data exposed or actions available, the precise impact is limited to unauthorized access.
Affected Systems
WordPress plugin Dariolee Netease Music, up to and including version 3.2.1. All installations of the plugin up to and including version 3.2.1 are potentially affected; newer releases may or may not contain this flaw.
Risk and Exploitability
The CVSS score of 4.3 suggests that compromised accounts or web requests can be abused without requiring advanced privileges. The EPSS score of less than 1% shows that currently the likelihood of active exploitation is low, and the vulnerability is not listed in CISA’s KEV catalog. However, the flaw remains present across a wide version range, making it a potential target for attackers who identify or craft a suitable request. The likely attack vector is web‑based, through the plugin’s front‑end forms, and may require an authenticated user context, although no explicit authentication requirement is stated.
OpenCVE Enrichment
EUVD