Impact
The WP Statistics plugin for WordPress contains a missing authorization flaw that permits attackers to exploit incorrectly configured access control settings. This weakness, classified as CWE-862, allows users who should not have privileged access to perform actions or view data reserved for administrators.
Affected Systems
WordPress sites utilizing the VeronaLabs WP Statistics plugin version 14.15 or earlier are affected. The vulnerability applies to all releases from the earliest available version through version 14.15, inclusive.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity. The EPSS score, being less than 1%, suggests a very low probability that the flaw is currently being actively exploited. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is through the web interface, where an unauthenticated or poorly authenticated user can access administrative functions of the plugin.
OpenCVE Enrichment
EUVD