Impact
The vulnerability is a missing authorization flaw that permits exploitation of incorrectly configured access control security levels within the Cron Logger plugin. It enables an attacker to gain unauthorized access to privileged functionality exposed by the plugin, potentially compromising the confidentiality and integrity of WordPress site operations such as schedule management or log data. The weakness is identified as CWE-862, a broken access control defect.
Affected Systems
The Cron Logger plugin from EdwardBock, versions up to and including 1.3.0, is affected. Any WordPress installation deploying this plugin version is potentially vulnerable.
Risk and Exploitability
The CVSS score of 4.3 places this issue in the moderate severity range, but the EPSS score of less than 1% indicates a very low likelihood of exploitation in the wild. The plugin is not listed in the CISA KEV catalog. Based on the description, the attack vector is inferred to be remote over the web; an attacker could send unauthorized HTTP requests to endpoints controlled by the plugin to bypass standard role checks.
OpenCVE Enrichment
EUVD