Impact
The wpDiscuz plugin contains a missing authorization flaw in its access control configuration, allowing an attacker to perform actions that are restricted by the WordPress role system. If the plugin’s security settings are incorrectly configured, malicious users can bypass normal restrictions and potentially edit or delete comments and other content handled by wpDiscuz, leading to unauthorized data modification.
Affected Systems
The vulnerability is present in AdvancedCoding wpDiscuz versions up to and including 7.6.33. Any WordPress installation that has not upgraded beyond version 7.6.33 is affected.
Risk and Exploitability
The CVSS score of 4.3 reflects a moderate severity, and the EPSS score of less than 1% indicates a very low likelihood of exploitation in the wild. The issue is not listed in CISA’s KEV catalog. A successful exploit would require the attacker to reach the wpDiscuz interfaces that rely on the broken access control, which are typically exposed on the public site. The absence of a known public exploit makes immediate patching prudent rather than relying on monitoring alone.
OpenCVE Enrichment
EUVD