Impact
The Traffic Monitor plugin for WordPress contains a missing capability check in the tfcm_maybe_set_bot_flags() function. This flaw allows an unauthenticated user to alter plugin settings and disable bot logging, thereby compromising the integrity of the site’s monitoring capabilities. The weakness is an Authorization issue (CWE-862).
Affected Systems
WordPress sites that have installed the dmitriamartin Traffic Monitor plugin, any version up to and including 3.2.2.
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves sending crafted HTTP requests to the plugin’s interface or accessing its administrative endpoints without authentication, which triggers the missing capability check.
OpenCVE Enrichment
EUVD