Impact
Missing authorization in BerqWP SearchPro allows a user to access protected functionality or data that should be restricted. This results in unauthorized read or potential manipulation of plugin settings, content or data through improperly configured security levels. The weakness is identified by CWE-862.
Affected Systems
BerqWP BerqWP SearchPro plugin, all versions up to and including 2.2.53, are affected.
Risk and Exploitability
With a CVSS score of 5.3 the vulnerability is considered moderate. The EPSS score of less than 1% indicates a very low likelihood of exploitation, and the vulnerability is not in the CISA KEV catalog. The likely attack vector is remote; an attacker can craft a request to the plugin’s endpoints without proper authentication and gain unauthorized access to protected resources. The impact is limited to the scope of the plugin and the user roles that the attacker can impersonate.
OpenCVE Enrichment
EUVD