Impact
The vulnerability is a missing authorization flaw in the DevItems Support Genix plugin that allows an attacker to bypass the access control mechanism. By exploiting incorrectly configured security levels, a user can gain privileges to perform actions reserved for higher‑privileged accounts, potentially exposing, modifying, or deleting content managed by the plugin. The weakness corresponds to CWE‑862: Missing Authorization.
Affected Systems
WordPress sites running the DevItems Support Genix plugin from any version up to and including 1.4.23 are affected.
Risk and Exploitability
With a CVSS score of 5.3 the vulnerability is considered moderate. The EPSS score is reported as less than 1%, suggesting a low probability of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog, and no public exploits have been documented. The effective attack vector is most likely through the web application, requiring a user with a WordPress account that can reach the plugin’s endpoints; no remote‑code execution was identified in the description.
OpenCVE Enrichment
EUVD