Impact
Missing authorization checks in the Posts Table with Search & Sort plugin allow an authenticated user to view or modify tables that should be restricted. This broken access control could let a low‑privilege account read private posts, comments, or other data, violating confidentiality and integrity. The weakness is CWE‑862.
Affected Systems
The Barn2 Plugins Posts Table with Search & Sort WordPress plugin, versions up to and including 1.4.10, is affected. Any WordPress site that has installed this plugin without enforcing proper role restrictions is at risk.
Risk and Exploitability
With a CVSS score of 5.3 the flaw is of moderate severity, and an EPSS score of less than 1% suggests low likelihood of exploitation. The plugin is not listed in the CISA KEV catalog, indicating no confirmed public exploits. The likely attack vector is an authenticated user with a low‑privilege role, as the vulnerability permits data access without role checks. Therefore the exploit path is reachable to any logged‑in user.
OpenCVE Enrichment
EUVD