Description
Unauthenticated Broken Access Control in Woostify Sites Library <= 1.6.2 versions.
Published: 2026-07-02
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A broken access control flaw exists in the Woostify Sites Library plugin for WordPress versions 1.6.2 and earlier, developed by Dylan Ngo. The weakness, classified as CWE‑862, allows an unauthenticated attacker to bypass authentication checks and gain access to administrative functions of the plugin. This can enable unauthorized viewing, modification, or deletion of content site administrators. The CVSS score of 5.3 indicates a moderate severity that does not provide arbitrary code execution but does compromise confidentiality’s content.

Affected Systems

WordPress sites that have the Woostify Sites Library plugin installed in the standard plugins directory and are running version 1.6.2 or earlier. The plugin, provided by Dylan Ngo, offers administrative routes that control site content and configuration.

Risk and Exploitability

The moderate CVSS score combined with an EPSS score of <1% suggests that exploitation is unlikely to be widespread, and the plugin is not listed in the CISA KEV catalog. Nevertheless, based on the description, it is inferred that issuing unauthenticated HTTP requests to the plugin’s admin URLs, allowing the attacker to bypass authentication requirements. This exposes the site’s administrative functions to public users, creating a significant risk of unauthorized content changes or data leakage if the plugin is not promptly patched.

Generated by OpenCVE AI on July 22, 2026 at 13:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Woostify Sites Library plugin to the latest available version that includes the fix.
  • Restrict access to the plugin’s administrative endpoints by firewall rules or host‑based access controls so that only authenticated users can reach them.
  • After applying the update and access restrictions, review the site for any unauthorized content or configuration changes that may have been made during the exposure period.

Generated by OpenCVE AI on July 22, 2026 at 13:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 02 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in Woostify Sites Library <= 1.6.2 versions.
Title WordPress Woostify Sites Library plugin <= 1.6.2 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-02T14:52:09.760Z

Reserved: 2025-11-21T11:20:58.862Z

Link: CVE-2025-66076

cve-icon Vulnrichment

Updated: 2026-07-02T14:52:06.347Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-22T14:00:04Z

Weaknesses