Impact
The CM On Demand Search And Replace plugin for WordPress contains a missing authorization flaw (CWE‑862). This flaw permits attackers to use the plugin’s search‑and‑replace features without proper permission checks. A successful exploitation could lead to unauthorized reading or alteration of site content, compromising data confidentiality and integrity.
Affected Systems
The vulnerability affects CreativeMindsSolutions’ CM On Demand Search And Replace plugin for WordPress, specifically all released versions up to and including 1.5.5.
Risk and Exploitability
The CVSS score is 4.3, indicating a moderate risk. The EPSS score is less than 1 % and the vulnerability is not listed in the CISA KEV catalog, suggesting a low probability of widespread exploitation. Based on the description, the likely attack vector involves reaching the plugin’s web‐facing endpoints; this inference is not explicitly stated in the CVE data. Nonetheless, the flaw is a web‑based access‑control weakness that could be exploited by a threat actor who can reach the plugin’s endpoints, making it prudent to address promptly.
OpenCVE Enrichment