Impact
A missing authorization check in the Pre‑Publish Post Checklist plugin allows an attacker to bypass access controls and perform actions that should be restricted. The flaw is a classic authorized‑drop for a privileged capability, giving attackers the potential to create, edit, or publish posts outside their normal permissions. This violates integrity and confidentiality of site content. The weakness corresponds to CWE‑862, an authorization bypass flaw.
Affected Systems
The vulnerability affects the danbriapps Pre‑Publish Post Checklist WordPress plugin in all releases up to and including version 3.1. Users hosting that plugin and not yet updated to a newer release are potentially exposed.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate impact when the plugin is accessed. The EPSS score of less than 1% shows a very low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, suggesting it has not been exploited at a significant scale yet. Likely attackers would need to authenticate to the site or exploit a user with elevated privileges to leverage this flaw, making the attack path local or remote but limited to those with some site access.
OpenCVE Enrichment
EUVD