Impact
The vulnerability is a missing authorization check in the Ivory Search add-search-to-menu component of the WordPress plugin, allowing attackers to bypass normal access restrictions and perform actions that should be limited to authenticated users. This flaw is classified as CWE‑862 (Missing Authorization) and can result in unauthorized disclosure, modification, or other actions on the website. The issue is caused by incorrect configuration of access control security levels that the plugin does not enforce.
Affected Systems
The affected product is the Ivory Search WordPress plugin from Vinod Dalvi, version 5.5.12 and all earlier releases. All WordPress sites that have installed the plugin and have not applied the latest patch are vulnerable, regardless of the WordPress core version.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, providing no additional evidence of active exploitation. Based on the description, it is inferred that an attacker might send specially crafted HTTP requests to the plugin’s endpoints to bypass authentication checks; in the absence of protective controls this could allow unauthorized postings, data manipulation, or other privileged actions.
OpenCVE Enrichment