Impact
Missing authorization checks in the MSN Partner Hub plugin allow attackers to perform actions beyond their intended permissions, potentially compromising the confidentiality, integrity, or availability of site data. The vulnerability arises from incorrectly configured access control security levels, enabling unauthorized users to interact with administrative functionality without proper credential verification. This flaw is identified as a CWE‑862 access control weakness.
Affected Systems
The affected product is the MicrosoftStart MSN Partner Hub WordPress plugin for versions up to and including 2.9. Any WordPress installation that has this plugin installed and not updated to a later release is vulnerable. No additional products or vendor combinations are listed.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score of less than 1% suggests a low likelihood of widespread exploitation. The vulnerability is not catalogued in CISA’s KEV list. Attackers could target publicly exposed administrative interfaces, leveraging the lack of authentication to elevate privileges. No specific exploit has been publicly disclosed, but the weak access controls make it theoretically feasible with standard web request techniques.
OpenCVE Enrichment