Impact
The Yext WordPress plugin contains a missing authorization flaw that allows an attacker to invoke plugin functions without proper access control. An attacker could trigger privileged operations by targeting the plugin’s endpoints, leading to unauthorized use of its capabilities. The weakness corresponds to CWE‑862, indicating an access control failure that can grant elevated privileges within the web application.
Affected Systems
WordPress installations running any build of the Yext Yext plugin up to and including version 1.1.3 are affected. Any site that has installed version 1.1.3 or earlier of the Yext plugin is susceptible; versions newer than 1.1.3 are presumed to contain the fix.
Risk and Exploitability
The CVSS base score of 5.3 reflects moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog, indicating no known widespread exploitation. The likely attack vector is external via HTTP requests, as the flaw resides on a web‑accessible plugin endpoint. An attacker with internet access to the site could send crafted requests to trigger the broken functionality without authenticating. While no active exploits are documented, the combination of a missing ACL and an internet‑facing surface creates a plausible scenario for abuse.
OpenCVE Enrichment
EUVD