Impact
The vulnerability is an unauthenticated broken access control flaw that allows any user to perform actions that should be restricted to authenticated users. Attackers could access and modify donation records, settings, or other protected resources. This weakness is classified as CWE-862 and carries a CVSS score of 5.3, indicating a moderate risk to confidentiality and integrity.
Affected Systems
The affected vendor is rhewlif, with the WordPress plugin Donation Thermometer. Versions up to and including 2.2.7 are vulnerable; any release beyond 2.2.7 is presumed fixed.
Risk and Exploitability
Because the flaw does not require authentication, the attack vector is likely remote over the web. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that it has not been widely exploited at the time of analysis. However, the moderate CVSS score still warrants prompt remediation to prevent unauthorized access or tampering.
OpenCVE Enrichment