Impact
This vulnerability is a Missing Authorization flaw that permits attackers to exploit incorrectly configured access control settings within the Bit Assist plugin. The result is unauthorized access to privileged plugin functions, which can lead to information disclosure, configuration changes, or other impact consistent with the CWE‑862 weakness. The stated CVSS score of 5.3 indicates a moderate severity for the vulnerability.
Affected Systems
The Bit Assist plugin for WordPress, from its initial version up to and including 1.5.11, is affected. All deployments that have not yet upgraded beyond version 1.5.11 are vulnerable.
Risk and Exploitability
The EPSS score of less than 1% implies a very low likelihood of exploitation in the observed attacker population. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the attack vector is remote and could be performed by any user that can reach the plugin’s administration interface without proper authorization checks. The moderate CVSS score reflects the availability of a remote attack path with limited but potentially useful impact. Users are advised that while exploitation is unlikely, the brute‑force potential remains, so timely mitigation is prudent.
OpenCVE Enrichment