Impact
The CVE describes a missing authorization flaw in the Roxnor EmailKit plugin that permits an attacker to delete content on a WordPress site. The vulnerability arises from incorrectly configured access control security levels, allowing any user with access to the plugin’s functionality to remove content. This can lead to loss of critical site data and disrupt site operations.
Affected Systems
The affected product is the Roxnor EmailKit plugin for WordPress, versions from the earliest release up to and including 1.6.0. System administrators should review any WordPress installations using this plugin version range.
Risk and Exploitability
The CVSS score of 4.9 indicates a moderate impact, and the EPSS score of less than 1% reflects low to negligible exploitation probability at the time of analysis. The vulnerability is not listed in CISA’s KEV catalog, further suggesting it has not been widely exploited. Nonetheless, the potential for mass content removal warrants immediate attention. The attack vector is inferred to be remote through authenticated (or possibly unauthenticated) web requests to plugin‑managed endpoints, and mitigation requires swift revision of access controls and plugin updates.
OpenCVE Enrichment
EUVD