Impact
The vulnerability in Ashish AI Tools for WordPress allows an attacker to delete content without proper authorization, compromising site integrity and potentially erasing important data. It is a missing authorization flaw that can lead to unintended deletion of posts, pages or other managed content objects, affecting the confidentiality of the site's material and negatively impacting user trust and operational availability.
Affected Systems
WordPress installations using the AI Tools plugin by Ashish, in all versions from the beginning of the plugin's releases through version 4.0.7 inclusive.
Risk and Exploitability
With a CVSS score of 6.5, the vulnerability poses a moderate to high severity, but its EPSS score of less than 1% indicates a low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to exploit incorrectly configured access control or an existing authenticated session with sufficient privileges; based on the description, the likely attack vector involves authenticated requests with elevated or misassigned permissions.
OpenCVE Enrichment
EUVD