Impact
The vulnerability is an Authorization Bypass through a User‑Controlled Key, often referred to as an Insecure Direct Object Reference. It permits an attacker to alter a key or parameter that the plugin uses to reference content or files, thereby gaining access to data that belongs to another user or role. This can result in the disclosure of confidential information or unauthorized changes, damaging the confidentiality and integrity of the site.
Affected Systems
The affected product is the Accessibility Checker plugin from Equalize Digital, used on WordPress websites. All plugin releases up to and including version 1.30.0 contain the flaw. Site administrators who have deployed this plugin should verify which version they are running and plan to update.
Risk and Exploitability
The CVSS score of 5.4 signifies moderate severity, and the EPSS score of less than 1% indicates a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Nevertheless, because the flaw permits an attacker to access or modify resources owned by other users, it can be serious if an exploitation path exists. The likely attack vector is web‑based; an attacker would need to craft requests that manipulate the exposed object identifiers, potentially using an existing authenticated session or CSRF. If successful, the attacker could read or alter content belonging to other users.
OpenCVE Enrichment
EUVD