Impact
A missing authorization flaw in the bobbingwide oik WordPress plugin allows attackers to exploit incorrectly configured access control security levels, giving them unauthorized access to protected administrative areas or other privileged functions. This flaw is a classic example of CWE-862, where insufficient integrity checks permit operations that should be restricted.
Affected Systems
The vulnerability affects the bobbingwide oik plugin for WordPress, specifically all releases from the initial release through version 4.15.1. Users running any of these versions are potentially exposed to unauthorized access.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The flaw is not listed in CISA’s KEV catalog, further implying limited widespread exploitation. Attackers would need to target a WordPress site running an affected oik plugin instance and could manipulate or bypass the plugin's access control settings to perform unauthorized actions. The lack of official patch information in the provided data means mitigation must rely on upgrading to a newer release or adjusting local configuration.
OpenCVE Enrichment
EUVD