Impact
Missing Authorization in the Nelio Content plugin version 4.0.5 and earlier allows attackers to abuse incorrectly configured access control settings. An authenticated or unauthenticated user could potentially access or modify protected content and administrative functions, compromising the confidentiality and integrity of the WordPress site.
Affected Systems
The vulnerability affects WordPress sites that have installed the Nelio Content plugin by Nelio Software with version 4.0.5 or older. No specific WordPress core version is mentioned, and the issue exists across all affected plugin releases.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and an EPSS score of less than 1% suggests a low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. The attack is likely carried out by exploiting administrative interfaces or API endpoints that are protected by incorrect access controls; this inference is derived from the description of the access control flaw.
OpenCVE Enrichment