Impact
The icc0rz H5P WordPress plugin contains a missing authorization flaw, identified as CWE‑862. The vulnerability allows a user with limited permissions to perform actions that should be reserved for higher‑privilege accounts. Likely, an attacker could view, edit, or delete content managed by H5P, thereby compromising the integrity and confidentiality of site data. The flaw does not grant full‑system control, but it does enable unauthorized access within the plugin’s scope.
Affected Systems
The affected product is the H5P WordPress plugin distributed by icc0rz. All releases from the earliest available version up to and including version 1.16.1 are vulnerable. No other vendors or products are listed as affected.
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity, while the EPSS score of less than 1 % suggests a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires that an attacker has some level of access to the WordPress site—either through an existing user account that can manipulate the plugin or by leveraging another authentication issue to gain sufficient privileges. The flaw allows privilege escalation within the plugin’s functions but does not enable remote code execution. Monitoring user accounts and reviewing plugin permissions is advisable.
OpenCVE Enrichment