Impact
The Appender plugin for WordPress contains a missing authorization check that permits users without sufficient privileges to perform actions that should be restricted. This flaw, identified as CWE‑862, could allow an attacker to read or modify sensitive data stored by the plugin, potentially exposing private information or altering site content.
Affected Systems
The vulnerability affects WordPress sites that have the merkulove Appender plugin version 1.1.1 or earlier installed. Any WordPress installation running one of these plugin releases is susceptible.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, while the EPSS score of less than 1 % suggests a low likelihood of exploitation at present. The flaw is not listed in CISA’s KEV catalog. Because the weakness is due to broken access control, an attacker could exploit it remotely by accessing the plugin’s web interface or exposed endpoints that lack proper permission checks. The impact would be unauthorized data disclosure or manipulation.
OpenCVE Enrichment