Impact
The vulnerability is a missing authorization flaw in the Gutentor WordPress plugin that allows an attacker with access to the site to perform privileged actions beyond their assigned role. Because the plugin does not enforce proper access control on certain endpoints, an attacker can manipulate content or user data, potentially compromising confidentiality and integrity of the site. This is identified as a CWE-862 mistake.
Affected Systems
The issue affects the Gutentor WordPress plugin version 3.5.5 and earlier, regardless of the WordPress core version. Site owners using any of those plugin releases are vulnerable. The plugin is published under the gutentor vendor name.
Risk and Exploitability
The CVSS score of 4.3 indicates a medium severity. The EPSS score of less than 1% suggests a low likelihood of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The flaw is likely exploitable via a web request to an admin endpoint that should be restricted to privileged users; thus, the attack vector is inferred to be a web-based remote exploitation. Users with sufficient technical knowledge could raise their own privileges or affect other users' data.
OpenCVE Enrichment
EUVD