Impact
The vulnerability is a missing authorization flaw in the Delisho WordPress plugin that allows attackers to misuse incorrectly configured security levels. It can lead to unauthorized access to plugin functionality or data, enabling operations that should be restricted. The weakness is classified as CWE-862, which reflects an authorization control failure.
Affected Systems
WP Delicious:Delisho plugin versions up to and including 1.1.3 are affected. No other product versions or vendors are listed as impacted.
Risk and Exploitability
The CVSS score of 4.3 indicates a low to moderate severity, and the EPSS score of less than 1% suggests a very low exploitation probability at the time of this analysis. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is application‑level; the description implies that an attacker could exploit configuration or privilege levels remotely once they have a web session, but explicit prerequisites are not detailed in the provided data.
OpenCVE Enrichment
EUVD