Impact
The WP Content Pilot plugin for WordPress contains a missing authorization flaw that allows attackers to bypass access controls. Classified as CWE-862, the vulnerability permits unauthorized users to perform restricted operations through the plugin, potentially exposing or altering content managed by the plugin. The CVSS score of 5.4 indicates a moderate risk to confidentiality and integrity.
Affected Systems
All versions of the WP Content Pilot plugin from the earliest release through 2.1.7 are affected. The flaw exists whenever the plugin is installed and configured on a WordPress site, regardless of other security settings.
Risk and Exploitability
The EPSS score is below 1 %, indicating a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. However, it can be abused by a remote attacker who can reach the plugin’s web‑based administration pages, allowing unauthorized data access or modification. The risk is mitigated by the requirement for direct site access, but the flaw remains exploitable under those conditions.
OpenCVE Enrichment