Impact
This vulnerability is an Authorization Bypass Through User-Controlled Key in the WordPress wpDiscuz plugin that allows an attacker to access or manipulate objects they should not be able to reach. The weakness is a classic Insecure Direct Object Reference (IDOR) and falls under CWE‑639. Exploitation can enable unauthorized viewing, editing, or deletion of comments or related data, potentially compromising content integrity and confidentiality.
Affected Systems
The wpDiscuz plugin for WordPress, developed by AdvancedCoding, is affected for all releases up to and including version 7.6.43. Users running these versions are exposed to the IDOR flaw.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, while the EPSS score of less than 1% suggests a low likelihood that this weakness will be actively exploited in the wild. It is not currently listed in the CISA KEV catalog. The attack vector is not explicitly stated in the advisory; the likely scenario is that an attacker crafts URLs or API requests that reference unauthorized object identifiers, as is common with IDORs. No other prerequisites are detailed in the provided description.
OpenCVE Enrichment