Impact
A missing authorization check in Evergreen Content Poster allows an attacker to bypass normal access controls and use the administrator functions of the plugin. The vulnerability is a classic missing authorization weakness (CWE‑862), which can let an unauthenticated or lower‑privilege user read, create, edit or delete content posted through the plugin.
Affected Systems
All installations of the Evergreen Content Poster plugin for WordPress, including versions up to and including 1.4.5.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. Although the EPSS score is less than 1 % and the vulnerability is not listed in the CISA KEV catalog, the exploit potential remains due to the lack of proper authorization checks. The likely attack vector involves HTTP requests to the plugin’s privileged endpoints, potentially via the website’s own access controls or through the WordPress REST API. An attacker with network access to the site could exploit the flaw without additional privileges.
OpenCVE Enrichment