Impact
The CodeablePress plugin for WordPress has a missing authorization flaw that allows attackers to gain unauthorized access to restricted functions related to the simple frontend profile picture upload feature. This incorrect access control can lead to the unauthorized modification or disclosure of user profile images, potentially compromising the integrity and confidentiality of user data. The vulnerability is classified as CWE‑862, highlighting a weakness in access control enforcement.
Affected Systems
The issue affects the CodeablePress plugin from early versions through 1.0.2 inclusive. Only installations running these vulnerable versions are at risk while newer releases have not been identified as impacted.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity, and the EPSS score of less than 1% shows that exploitation likelihood is low at the time of analysis, with the vulnerability not listed in the CISA KEV catalog. The attack vector is likely remote via the WordPress web interface, where an unauthenticated or low‑privileged user could trigger uploads or other operations that bypass normal access controls. Because the flaw is an authorization bypass rather than an injection or code‑execution bug, the preconditions for exploitation are limited to the presence of the vulnerable plugin and a valid WordPress installation.
OpenCVE Enrichment
EUVD