Impact
A missing authorization flaw in the Climax Themes Kata Plus WordPress plugin permits an attacker to exploit incorrectly configured access control security levels. The vulnerability allows unauthorized users to perform actions that should be restricted, potentially enabling the creation, modification, or deletion of posts, settings, or other protected resources. The weakness is catalogued as CWE‑862, a classic broken access control issue, and could lead to unauthorized content manipulation, privacy breach, or exposure of sensitive data if not stopped.
Affected Systems
Climax Themes Kata Plus plugin, versions up to and including 1.5.3, is affected. Any website running Kata Plus in this version range is vulnerable.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, and the EPSS score of less than 1% shows a very low likelihood of exploitation currently. The vulnerability is not listed in the CISA KEV catalog. Attackers would likely deliver the exploit via HTTP requests to plugin‑specific URLs that lack proper permission checks; the attack can be launched from a remote web client once the target site hosts the vulnerable plugin. No additional requirements are specified.
OpenCVE Enrichment
EUVD