Impact
Missing authorization in the CBX Bookmark & Favorite plugin allows attackers to exploit incorrectly configured access control security levels, potentially enabling them to view or modify bookmark and favorite data without proper privileges. The vulnerability does not provide remote code execution but can lead to unauthorized disclosure or tampering of user data within the affected WordPress site.
Affected Systems
All WordPress sites that install Sabuj Kundu CBX Bookmark & Favorite plugin version 2.0.1 or earlier are impacted. The vulnerability applies from the earliest available version through 2.0.1 inclusive.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate risk, and the EPSS score of less than 1% suggests a low probability of exploitation at this time. This CVE is not listed in the CISA KEV catalog. Based on the description, it is inferred that attackers can exploit the flaw by sending crafted HTTP requests directly to the plugin’s endpoints without authentication, taking advantage of the missing access control checks. The impact is confined to authorized data operations rather than system compromise.
OpenCVE Enrichment