Impact
The vulnerability is a broken access control flaw in the WordPress Text To Speech TTS Accessibility plugin that allows attackers to exploit incorrectly configured security levels. Because the plugin lacks proper authorization checks, users with certain privileges or even unauthenticated visitors can access or manipulate protected resources. The potential impact ranges from unauthorized data exposure to the execution of unintended plugin actions, compromising confidentiality and integrity of content served by the site. The weakness is classified as CWE‑862.
Affected Systems
This issue affects the WordPress plugin Azizul Hasan Text To Speech TTS Accessibility, versions from the earliest released version up to and including 1.9.30. Sites that have deployed any of those plugin releases are potentially vulnerable.
Risk and Exploitability
The flaw carries a CVSS score of 4.3, indicating moderate risk, and an EPSS score of <1 %, meaning exploitation is expected to be rare. The plugin is not listed in CISA’s KEV catalog, and no publicly known exploit code exists. The likely attack vector involves accessing the plugin’s administrative endpoints via the WordPress interface; an attacker would need only authenticated access with a role that has permission to manage plugins or could be able to send crafted requests to endpoints that do not enforce proper checks. Provided the exploit requires only user authentication, the threat is limited to users with privileges that can bypass the typical role restrictions.
OpenCVE Enrichment
EUVD