Impact
The flaw is a missing authorization vulnerability that permits users without appropriate privileges to trigger the plugin’s scraping and post‑generation features. This weakness is classified as CWE‑862, indicating improper enforcement of access control. An attacker who can reach the exposed plugin endpoints could initiate content scraping or automated post creation that were intended to be restricted to privileged users.
Affected Systems
"CodeRevolution’s Crawlomatic Multisite Scraper Post Generator" plugin for WordPress, all releases up to and including version 2.6.8.2.
Risk and Exploitability
The CVSS score of 4.3 is considered moderate, and the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is via remote HTTP requests to the plugin’s endpoints on a WordPress site, exploiting the lack of access checks.
OpenCVE Enrichment
EUVD