Impact
This issue manifests as a missing authorization check in the WANotifier Notifier WordPress plugin. Because the plugin fails to verify that a caller has sufficient privileges, an attacker could trigger actions or view data that should be restricted to authenticated administrators. The root weakness is a CWE‑862 Missing Authorization defect, meaning access controls are not enforced properly.
Affected Systems
The vulnerability affects the WANotifier Notifier WordPress plugin, version 2.7.13 and all earlier releases. No other vendors or products are listed as impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity overall. The EPSS score of <1% suggests that, at present, the probability of exploitation observed in the wild is quite low, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, because the plugin operates within a web application environment, an attacker could access the vulnerable functions remotely if proper authentication is bypassed; the exact attack vector is not specified in the advisory, but it is inferred that remote exploitation via the WordPress interface would be the likely path.
OpenCVE Enrichment