Impact
The vulnerability is a missing authorization flaw that allows exploitation of incorrectly configured access control security levels in the Notification for Telegram plugin. It enables users who do not normally have permission to access or modify the plugin’s configuration, potentially permitting them to send arbitrary messages or modify bot settings. This is a broken access control weakness (CWE-862) that can lead to unauthorized use of the messaging capability and compromise the integrity of the site’s communications.
Affected Systems
The issue affects the WordPress Notification for Telegram plugin by rainafarai, for all releases from the earliest available version through version 3.5.1. Any WordPress site that has installed this plugin within that version range is impacted.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate impact with limited privileges required. The EPSS score is less than 1%, showing a very low probability of exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector requires a user with WordPress credentials that can reach the plugin’s settings page or otherwise trigger the vulnerable functionality; no public exploits are documented. Sites with loose role assignments that allow non-administrator users to access the plugin are at greater risk, but the overall threat remains low until a patch is applied.
OpenCVE Enrichment