Impact
The Accessibility by AudioEye plugin contains a missing authorization flaw that allows an attacker to bypass access control checks and gain unauthorized access to protected functionality. The weakness corresponds to CWE‑862. An attacker who exploits this can read or modify plugin settings, potentially leading to a broader compromise of the WordPress site.
Affected Systems
Any WordPress installation that has the Accessibility by AudioEye plugin version 1.0.49 or earlier is impacted. The vulnerability exists across all supported WordPress versions where these plugin versions are deployed.
Risk and Exploitability
The CVSS score of 4.3 indicates a low‑to‑medium severity, and the EPSS score of less than 1 % suggests a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via the plugin's exposed configuration pages or endpoints; an attacker would need to provide valid credentials to trigger the access‑control bypass, meaning that the exploitation risk is higher for privileged users with access to the WordPress admin area.
OpenCVE Enrichment