Impact
The vulnerability is a missing authorization flaw (CWE-862) in the VW Themes Ibtana WordPress visual editor plugin that allows an attacker to delete content without proper permission. The flaw stems from incorrectly configured access control security levels for administrative actions. As a result, exposed endpoints can be invoked to remove posts, pages, or other content, leading to loss of data integrity and availability.
Affected Systems
This issue affects the Ibtana Visual Editor plugin for WordPress, distributed by VW Themes as Ibtana. Versions up to and including 1.2.5.3 are vulnerable; no minimum affected version is documented. Any WordPress site that hosts the plugin and does not apply the recommended patch or upgrade is impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% suggests a low likelihood of widespread exploitation at present. The vulnerability is not listed in the CISA KEV catalog, further implying limited active exploitation. However, the attack flow is straightforward and can be performed remotely by accessing the plugin’s deletion functions without proper authorization, allowing an attacker to delete arbitrary content if they can reach the vulnerable endpoint.
OpenCVE Enrichment
EUVD