Impact
A Missing Authorization vulnerability in the WP Grids EasyTest plugin allows attacker exploitation of incorrectly configured access control settings. This flaw enables unauthorized users to access administrative functions and data that should be restricted, potentially leading to disclosure or modification of sensitive site information.
Affected Systems
The vulnerability targets the WP Grids EasyTest plugin, affecting all releases from the earliest version up to and including 1.0.1.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The issue is not listed in the CISA KEV catalog. Attackers can likely exploit the flaw by sending unauthenticated or mis‑authenticated HTTP requests to the plugin’s protected endpoints. Because the problem is a broken access control, success requires the attacker to reach the vulnerable functionality, implying that clients exposed to the public web face some risk.
OpenCVE Enrichment