Impact
The vulnerability in the Media Author plugin is caused by incorrect privilege assignment, allowing a user with lower privileges to perform actions reserved for administrators. This broken access control flaw can elevate an attacker’s privileges within a WordPress site. The weakness is identified as CWE-266.
Affected Systems
The affected product is the Media Author plugin developed by John Luetke. Versions up to and including 1.0.4 are vulnerable. WordPress sites that host this plugin, regardless of the core WordPress version, are at risk.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate impact. The EPSS score of less than 1% reflects a low likelihood of exploitation in the wild. The vulnerability is not in the CISA KEV catalog, suggesting no known mass exploitation. Based on the description, it is inferred that the attacker must be authenticated to the site; with a lower privilege level than an administrator, the attacker can manipulate the plugin to elevate their own privileges.
OpenCVE Enrichment
EUVD