Impact
The Wikipedia Preview plugin for WordPress contains a Missing Authorization flaw that allows an attacker to exploit incorrectly configured access control security levels. This vulnerability is classified as CWE‑862, indicating a failure to enforce proper access permissions. As a result, an attacker could read, edit, or potentially delete content without proper authorization, compromising both confidentiality and integrity of the site. The impact is limited to the scope of the WordPress installation where the plugin is active.
Affected Systems
The issue affects Wikimedia Foundation’s Wikipedia Preview plugin version 1.15.0 and earlier. Any WordPress site that has installed or is running the plugin on these or older versions is susceptible. Exact version numbers beyond 1.15.0 are not listed; newer releases are assumed to contain the fix.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity vulnerability. The EPSS score of less than 1% suggests a very low likelihood of exploitation at the time of analysis, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the attack vector is likely through the plugin’s preview functionality, which may be accessible to users with minimal authentication or potentially unauthenticated victims if the feature is exposed. The lack of explicit prerequisites implies that exploitation could occur in a typical WordPress environment that has the plugin installed and active.
OpenCVE Enrichment