Impact
The WP Delicious plugin suffers from a missing authorization flaw that allows attackers to perform unauthorized actions on recipe data, potentially exposing or modifying content and undermining data integrity.
Affected Systems
The vulnerability affects the WP Delicious WordPress plugin for all releases from the initial launch through version 1.9.1. Users running any of these versions are susceptible.
Risk and Exploitability
With a CVSS score of 6.5 the issue presents medium severity; the EPSS score indicates exploitation probability below 1%, and it is not listed in the CISA KEV catalogue. The flaw can be triggered by a web request to the plugin’s endpoints without prior authentication, making it exploitable over the public web surface.
OpenCVE Enrichment