Impact
The vulnerability is a missing authorization flaw in the Ninja Team GDPR CCPA Compliance Support WordPress plugin. It allows attackers to bypass expected access controls and manipulate or expose restricted configuration settings. This incorrect configuration can lead to unauthorized access to sensitive compliance data or administrative functions, undermining confidentiality and potentially allowing further exploitation within the WordPress environment. The weakness is classified as CWE-862.
Affected Systems
The issue affects the Ninja Team GDPR CCPA Compliance Support plugin for WordPress versions from the initial release through v2.7.4. Any site running the plugin within this version range is potentially vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack likely requires the attacker to discover a plugin endpoint that is not properly protected, and then to send requests to that endpoint without authenticating. The exact attack vector is not explicitly documented, but the presence of a missing authorization check implies that unauthenticated or improperly authenticated users could exploit the flaw.
OpenCVE Enrichment