Impact
The reported vulnerability is a missing authorization flaw that enables an attacker to exploit incorrectly configured access control security levels in the F4 Media Taxonomies WordPress plugin. This flaw, identified as CWE-862, allows an actor with sufficient privileges to bypass the intended permissions and perform actions on media taxonomy data that they should not be able to access or modify, potentially leading to unauthorized data exposure or tampering.
Affected Systems
The vulnerability affects the WordPress plugin F4 Media Taxonomies by FAKTOR VIER for all releases from the initial version up to and including version 1.1.4. No later releases are known to be impacted.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity, while an EPSS score of less than 1% suggests a very low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, and no confirmed exploits have been reported. Based on the description, it is inferred that the likely attack vector involves compromising a user account or leveraging an existing administrative role to manipulate taxonomy permissions through the plugin’s misconfigured access controls.
OpenCVE Enrichment
EUVD