Impact
The vulnerability allows a user to bypass authorization controls by using a controllable key, leading to an insecure direct object reference. An attacker could gain access to or modify objects that should be restricted, potentially exposing sensitive data or altering configuration settings. This is a classic IDOR flaw identified as CWE-639.
Affected Systems
The MyD Delivery plugin by Eduardo Villão for WordPress, versions n/a through 1.7.1, are affected. Any WordPress site using these plugin versions is at risk.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in CISA KEV. The likely attack vector is through the web interface of the plugin, where an attacker can supply a user-controlled key. Exploitation may require authenticated access or could be possible as an unauthenticated user depending on the plugin's access control settings.
OpenCVE Enrichment