Impact
The plugin fails to enforce proper authorization, enabling users without sufficient privileges to access or modify content and settings that should be restricted. This weakness is identified as CWE-862. Attackers could read, edit, or delete content belonging to other users or administrators, which may result in unauthorized disclosure or tampering of information.
Affected Systems
The vulnerability affects the WordPress Read More & Accordion plugin (edmon.parker expand-maker) for all releases from the initial version up to and including 3.5.5.1. Any installation of the plugin in that version range is vulnerable.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate impact. The EPSS score of less than 1 % suggests the probability of exploitation is currently low, and the vulnerability is not listed in CISA’s KEV catalog. The lack of an explicit attack vector in the description implies that exploitation would likely come from standard user interactions with the plugin interface, meaning it could be abused remotely by authenticated users with limited permissions. Organizations should assess whether such users exist and the criticality of data exposed through the plugin.
OpenCVE Enrichment