Impact
Missing Authorization in the Revive Old Posts WordPress plugin removes critical access controls. Because the plugin does not enforce proper authentication or role checks, an attacker can manipulate post‑retention settings or other configuration options. The vulnerability is categorised as CWE‑862 and can undermine the confidentiality, integrity, and availability of site content, potentially allowing an unauthenticated or low‑privileged user to alter or delete posts.
Affected Systems
WordPress sites that use the Revive Old Posts plugin version 9.3.3 or older are affected. No specific earlier versions are listed, so any release prior to or equal to 9.3.3 may contain the flaw. The plugin is distributed by rsocial and is available as the tweet‑old‑post WordPress plugin.
Risk and Exploitability
The CVSS score of 4.3 indicates a low base severity. EPSS is below 1%, suggesting very limited exploitation activity at this time. The vulnerability is not currently listed in the CISA KEV catalog. Attackers would likely target the plugin through a web interface, possibly leveraging an existing user session or exploiting very weak role checks; the lack of proper authorization implies that even non‑admin users could access privileged plugin configuration pages.
OpenCVE Enrichment