Impact
A missing authorization defect (CWE‑862) in Skynet Technologies USA LLC’s All in One Accessibility WordPress plugin permits exploitation of incorrectly configured access control settings, allowing an attacker to reach the plugin’s administration pages without proper authorization.
Affected Systems
Versions of the All in One Accessibility plugin from the initial release through 1.15 are vulnerable; any WordPress site that has installed the plugin in one of those versions is affected.
Risk and Exploitability
The CVSS score of 4.3 ranks the flaw as moderate; an EPSS score of less than 1 % indicates a very low likelihood of exploitation at the time of analysis. The vulnerability is not listed in CISA’s KEV catalog. Attackers would target the plugin’s exposed administrative interfaces through normal web access; no additional conditions are described in the official advisory.
OpenCVE Enrichment