Impact
The vulnerability is a missing authorization flaw in the DMCA Protection Badge plugin that allows users to perform actions normally restricted to privileged accounts. The incorrect configuration of access control security levels means that any authenticated user could modify plugin settings, potentially exposing DMCA notices or bypassing protection mechanisms. This weakness is classified under CWE‑862 and could compromise the confidentiality and integrity of protected content.
Affected Systems
The affected system is NewClarity’s DMCA Protection Badge plugin for WordPress. All releases from the initial appearance up to and including version 2.2.0 are impacted. No specific affected versions beyond 2.2.0 are listed.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in CISA KEV. The likely attack vector is via the WordPress admin interface or plugin configuration pages, based on the description, it is inferred that an attacker could interact with these to bypass access restrictions. Because no authentication bypass is described, the threat level remains moderate but still warrants remediation.
OpenCVE Enrichment