Impact
The IgnitionDeck plugin contains a missing authorization flaw that permits an attacker to bypass security checks and access functions or data that should be protected. This can lead to disclosure of sensitive information, alteration of content, or other unauthorized modifications. The vulnerability is classified as CWE-862 and has a CVSS score of 5.4, indicating a moderate level of risk.
Affected Systems
WordPress sites that have the IgnitionDeck plugin (ignitionwp:IgnitionDeck) installed at versions 2.0.15 or earlier are affected. All versions from the initial release through version 2.0.15 are vulnerable.
Risk and Exploitability
The CVSS score of 5.4 places the vulnerability in the Moderate range, while the EPSS score of less than 1% indicates a low probability of active exploitation in the wild. Based on the description, the likely attack vector is through the plugin’s publicly accessible web endpoints; the missing authorization check allows remote exploitation without valid credentials. The vulnerability is not listed in the CISA KEV catalog, yet the availability of a patch makes remediation advisable to prevent potential unauthorized activity.
OpenCVE Enrichment