Impact
Missing authorization controls in the Subscribe to Download plugin allow an attacker to exploit incorrectly configured access level checks. The flaw can enable an attacker with insufficient privileges to perform protected actions or retrieve sensitive data that should be restricted. This type of vulnerability leads to compromising confidentiality or integrity of downloaded content and could facilitate further exploitation of the site.
Affected Systems
All WordPress sites running the wpshuffle Subscribe to Download plugin version 2.0.9 or earlier are affected. The vulnerability exists across all versions from the initial release through 2.0.9.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity. The EPSS score of less than 1% suggests that exploitation is unlikely to be widespread, and the vulnerability has not been listed in CISA's KEV catalog. Based on the description, the likely attack vector—though not explicitly stated—is inferred to involve web requests to the plugin’s administrative and download endpoints. It may be exploitable by authenticated users lacking proper permissions or potentially by unauthenticated users, depending on configuration. Nevertheless, the opportunity for unauthorized access warrants remediation.
OpenCVE Enrichment
EUVD