Impact
The Grand Conference Theme Custom Post Type plugin contains a missing authorization flaw that lets attackers bypass the intended access controls. An exploited instance could enable an unauthenticated or low‑privileged user to view, edit, or delete site content and configuration data, thereby affecting the confidentiality and integrity of the website’s material.
Affected Systems
The vulnerability affects the WordPress plugin "Grand Conference Theme Custom Post Type" by ThemeGoods. All installations using any version prior to 2.6.4 are potentially vulnerable, including both standard and custom deployment configurations of the plugin.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. The EPSS score of less than 1% suggests a low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a web‑based request directed at the plugin’s administrative endpoints, exploiting insufficient capability checks. No public exploit code is known, but the flaw could be leveraged by any user able to craft a request to the vulnerable plugin.
OpenCVE Enrichment
EUVD