Impact
The vulnerability is an Insecure Direct Object Reference that allows an attacker to bypass authorization checks by supplying a user‑controlled key. This results in unauthorized access to documents stored by the Barn2 Plugins Document Library Lite plugin, effectively granting an attacker the ability to read or download sensitive files that should otherwise be restricted. The weakness is classified as CWE‑639, indicating a flaw in access control logic.
Affected Systems
WordPress sites that use the Barn2 Plugins Document Library Lite plugin. All installations running version 1.1.7 or earlier are affected, while newer releases are not listed as vulnerable.
Risk and Exploitability
The CVSS score of 5.3 places the vulnerability in the moderate severity range. The EPSS score of less than 1% indicates a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker can construct a URL containing a valid or guessed resource key to directly retrieve a protected document without needing to authenticate.
OpenCVE Enrichment