Impact
The vulnerability is a missing authorization flaw in MSTW CSV EXPORTER that allows an attacker to trigger exports without proper permission checks. This could expose sensitive data from the WordPress site or be used for further privilege escalation. It originates from incorrectly configured access control security levels and represents a classic permission grant weakness (CWE‑862).
Affected Systems
Mark O'Donnell’s MSTW CSV EXPORTER plugin for WordPress, versions up to and including 1.4. All earlier releases are also affected.
Risk and Exploitability
The CVSS score of 5.3 places the issue in the medium severity range. The EPSS score of less than 1% indicates very low current exploit probability, and the vulnerability is not listed in the CISA KEV catalog. Exploitability would likely require an authenticated user or user with unrestricted access to the export endpoint; an attacker with such access can trigger the flaw to retrieve data. No known public exploits have been reported.
OpenCVE Enrichment