Impact
The GoDAM plugin for WordPress suffers from a missing authorization check that allows users to exploit incorrectly configured access control levels, which can enable unauthorized access to plugin configuration data and potentially other protected content. The vulnerability is classified as a broken access control weakness (CWE-862). Attackers who exploit this flaw could read or modify information normally restricted to privileged users, compromising the confidentiality and integrity of the site.
Affected Systems
The issue affects all installations of the rtCamp GoDAM plugin up to and including version 1.4.6. No specific minor versions are singled out; any deployment of GoDAM 1.4.6 or older is vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, while the EPSS score of less than 1% suggests a very low likelihood of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Based on the plugin’s web‑based nature, the likely attack vector involves HTTP requests crafted by an attacker to bypass the plugin’s access checks, making the flaw exploitable through the web interface or by directly accessing protected URLs.
OpenCVE Enrichment