Impact
The vulnerability is an access control flaw in the DocsPress plugin for WordPress that allows an attacker to bypass configured security levels and gain unauthorized access to protected documents. Because the plugin fails to enforce authorization checks, a low‑privileged user could view sensitive content or modify it. The weakness is classified as CWE‑862.
Affected Systems
Affected products are the DocsPress plugin from the nK vendor, versions up to and including 2.5.2. WordPress sites that use this plugin at those versions are vulnerable.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score of <1 % shows a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an attacker sending crafted HTTP requests that exploit the missing authorization checks on a site where the plugin is installed and misconfigured, typically by triggering the bypass. While the risk is moderate, the potential for data exposure warrants prompt remediation.
OpenCVE Enrichment
EUVD