Impact
The VG WORT METIS plugin for WordPress lacks a capability check in its gutenberg_save_post() function, allowing authenticated users with Subscriber-level privileges or higher to update limited post settings when saving via the Gutenberg editor. This results in unauthorized data modification, potentially altering post configuration without appropriate authorization. The weakness is an authorization flaw (CWE-862). The impact is confined to post settings, but it enables attackers to change content behavior or presentation without gaining higher-level access.
Affected Systems
Any WordPress installation that uses the VG WORT METIS plugin with version 2.0.0 or earlier is affected. Versions before 2.0.0 are confirmed vulnerable; newer releases contain a patch that removes this issue.
Risk and Exploitability
The CVSS score of 4.3 indicates low severity, and the EPSS score of less than 1% suggests a very low likelihood of exploitation. The vulnerability is not listed in CISA KEV. However, because the flaw requires only an authenticated Subscriber or higher user, any site with such accounts can potentially exploit the vulnerability. The risk remains low to medium due to the limited scope of the damage, but administrators should address it promptly.
OpenCVE Enrichment
EUVD