Impact
A broken access control flaw exists in the Woostify Sites Library plugin for WordPress versions 1.6.2 and earlier, developed by Dylan Ngo. The weakness, classified as CWE‑862, allows an unauthenticated attacker to bypass authentication checks and gain access to administrative functions of the plugin. This can enable unauthorized viewing, modification, or deletion of content site administrators. The CVSS score of 5.3 indicates a moderate severity that does not provide arbitrary code execution but does compromise confidentiality’s content.
Affected Systems
WordPress sites that have the Woostify Sites Library plugin installed in the standard plugins directory and are running version 1.6.2 or earlier. The plugin, provided by Dylan Ngo, offers administrative routes that control site content and configuration.
Risk and Exploitability
The moderate CVSS score combined with an EPSS score of <1% suggests that exploitation is unlikely to be widespread, and the plugin is not listed in the CISA KEV catalog. Nevertheless, based on the description, it is inferred that issuing unauthenticated HTTP requests to the plugin’s admin URLs, allowing the attacker to bypass authentication requirements. This exposes the site’s administrative functions to public users, creating a significant risk of unauthorized content changes or data leakage if the plugin is not promptly patched.
OpenCVE Enrichment