Impact
The vulnerability is a missing authorization flaw that permits the exploitation of incorrectly configured access control security levels. An attacker can gain unauthorized access to plugin features and potentially manipulate data or execute privileged actions. The weakness is formally classified as CWE-862, which focuses on missing authorization constraints.
Affected Systems
WordPress users who have installed the bPlugins Tiktok Feed plugin in any version up to 1.0.23, including older builds with unspecified earlier versions. The issue affects the plugin’s WordPress interface and any endpoints it exposes, regardless of the site’s configuration.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of widespread exploitation at present. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The likely attack vector is a web-based request to the plugin’s exposed endpoints; it is inferred that an attacker could craft requests once authentication is present or, depending on configuration, potentially without prior login. This flaw does not require code execution or privilege escalation beyond the compromised access level, but it can allow an actor to bypass intended role restrictions.
OpenCVE Enrichment