Impact
The vulnerability is a missing authorization error in the ONTRAPORT PilotPress plugin that enables attackers to bypass configured access control security levels. Without the expected checks, an attacker with knowledge of plugin endpoints can potentially gain unauthorized access to restricted functions or data.
Affected Systems
ONTRAPORT PilotPress plugin versions 2.0.36 and earlier on WordPress sites.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate risk, while the EPSS score of less than 1% shows a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker could exploit the flaw remotely by sending crafted requests to plugin endpoints when access control is misconfigured.
OpenCVE Enrichment
EUVD