Impact
An attacker can bypass authorization checks in the ArtistScope CopySafe Web Protection WordPress plugin when the plugin is running any version up to 5.1. This missing authorization flaw is aligned with CWE-862 and allows the exploitation of incorrectly configured access control security levels. Once an attacker gains access, they can execute privileged functions or obtain sensitive data that should be restricted to legitimate administrators.
Affected Systems
The vulnerability affects the WordPress CopySafe Web Protection plugin released by ArtistScope. All instances of the plugin with a version number up to and including 5.1 are susceptible. No other products or newer versions are reported to be impacted.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. The EPSS score of <1% suggests the probability of exploitation observed in the wild is very low, and it is not currently listed in the CISA KEV catalog. The likely attack vector is web‑based, where an adversary submits malicious requests to plugin endpoints that lack proper authorization checks. If successful, the attacker can elevate privileges within the WordPress site.
OpenCVE Enrichment
EUVD