Impact
The AFS Analytics WordPress plugin contains a missing authorization flaw that permits users to invoke functions that should be limited to privileged users. Attackers can call these endpoints without proper permissions, potentially exposing sensitive site data or configuration. This weakness is a classic example of a missing authorization flaw (CWE‑862).
Affected Systems
The vulnerability impacts all installations of the AFS Analytics plugin up to and including version 4.21. Users running WordPress with this plugin should check their installed version and ensure it is not within the affected range.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of < 1 % suggests that exploitation is unlikely but not impossible. The vulnerability is not listed in the CISA KEV catalog. The attack vector most likely involves sending crafted HTTP requests to the plugin’s API endpoints, which are accessible from the web front end and do not enforce proper access controls.
OpenCVE Enrichment
EUVD