Impact
This defect in the Alex Content Mask WordPress plugin enables an attacker to bypass authorization controls by manipulating user‑controlled keys as described in the CVE. The CVE identifies this as a CWE‑639 Authorization Bypass Through User‑Controlled Key. Based on the description, the flaw could allow an unauthenticated or low‑privilege user to retrieve or modify content that should be restricted; this impact is inferred from the nature of the vulnerability.
Affected Systems
All WordPress sites that use the Content Mask plugin from the vendor Alex, versions up to and including 1.8.5.3, are affected. No other vendors or products are listed as impacted by this issue.
Risk and Exploitability
The CVSS score of 3.8 indicates a low to medium severity. The EPSS score is below 1%, indicating a low probability of exploitation at the time of analysis, and the vulnerability is not catalogued as a priority by CISA. Based on the description, the likely attack vector involves HTTP requests to the plugin’s endpoints where an attacker may manipulate user‑controlled keys to access protected content; this inference is drawn from the stated authorization bypass. Exploitation does not require elevated privileges, suggesting that it could be attempted by anyone with network access to the site.
OpenCVE Enrichment
EUVD