Impact
Missing Authorization (CWE‑862) in Liton Arefin WP Adminify allows exploitation of incorrectly configured access control security levels. An attacker can gain unauthorized administrative capabilities without proper authentication, potentially modifying site content, settings or accessing sensitive data. The flaw impairs confidentiality, integrity, and availability by granting full control over the WordPress installation.
Affected Systems
Liton Arefin’s WP Adminify plugin is affected from all versions up to and including 4.0.6.1. Users running any of these versions on WordPress sites are vulnerable. The plugin provides administrative tools, so any WordPress instance that has the plugin installed and configured with default or inadequate access settings is at risk.
Risk and Exploitability
The CVSS score of 4.3 indicates a medium severity flaw, while an EPSS score of less than 1 percent suggests a low exploitation probability at present. It is inferred that the plugin’s web‑based interface is the likely attack surface, and that the missing authorization check indicates that no valid authentication is required to achieve elevated privileges. Though listed as not in KEV, the absence of a known public exploit does not diminish the risk for organizations that have the vulnerable plugin installed.
OpenCVE Enrichment