Impact
The vulnerability is a missing authorization flaw in the WordPress My Tickets plugin, allowing attackers to execute actions or view content that should be restricted based on role or privilege. The issue permits unauthorized access to administrative functions or sensitive data provided through the plugin’s web interface, which can result in information disclosure or manipulation of ticketing data.
Affected Systems
Joe Dolson’s My Tickets plugin, affecting all installations of version 2.1.0 and earlier.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate security impact, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is a web-based request to privileged pages or actions within the plugin, exploiting the lack of proper role checks.
OpenCVE Enrichment