Impact
Missing authorization controls in the Editorial Calendar plugin allow properly authenticated users to bypass security level checks and execute administrative actions that should be restricted. This flaw can enable a non-privileged user to modify, delete, or schedule posts, and potentially leak editorial workflow data. The vulnerability is a classic missing authorization issue (CWE‑862).
Affected Systems
Marketing Fire’s Editorial Calendar plugin for WordPress, versions up to and including 3.8.8. Any site that has installed this plugin without updating beyond 3.8.8 is vulnerable.
Risk and Exploitability
The CVSS score of 5.4 indicates medium severity, and the EPSS score of less than 1% suggests a low likelihood of widespread exploitation at present. The flaw is not listed in CISA’s KEV catalog. Attackers would likely target the plugin’s administrative interface via typical WordPress HTTP requests and would need authenticated access, but the lack of proper role enforcement could grant elevated privileges to users who normally should not have them.
OpenCVE Enrichment