Impact
A missing authorization check in the Ergonet Cache plugin permits an unauthenticated attacker to access data that should be protected, such as cached pages and potentially sensitive administrative functions. The core weakness is CWE‑862, indicating an incorrect enforcement of access control that allows unauthorized data disclosure or manipulation.
Affected Systems
The vulnerability exists in WordPress sites running Ergonet Cache version 1.0.13 or earlier. Any installation of the plugin at or below this version is impacted.
Risk and Exploitability
The CVSS score of 4.3 reflects a moderate impact; the EPSS score of less than 1 % indicates a very low probability of exploitation under current conditions, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the likely attack vector is remote web access through the plugin’s exposed HTTP endpoints, requiring no special credentials or local compromise.
OpenCVE Enrichment