Impact
The Aardvark Plugin for WordPress contains a missing authorization flaw that allows remote actors to gain unauthorized access to administrative functionalities. By exploiting improperly configured access control security levels, an attacker can read or manipulate plugin data, effectively escalating privileges within the WordPress environment. The weakness is identified as CWE‑862, indicating a failure to enforce proper authorization. No direct damage to the core WordPress installation is described, but the plugin’s administrative scope can lead to unauthorized configuration changes, data leakage, or further exploitation.
Affected Systems
GhostPool Aardvark Plugin, a WordPress plugin, is affected for all releases up to and including version 2.19. The vulnerability applies to any WordPress installation that has this plugin enabled, regardless of the specific site configuration.
Risk and Exploitability
With a CVSS score of 7.5 the flaw is considered high severity. The EPSS score is under 1%, indicating that exploitation is currently unlikely. The vulnerability is not present in the CISA KEV catalog. Attackers can exploit it via the web by sending requests to the plugin’s administrative routes, assuming the site has the plugin enabled with insufficient access restrictions. Because the flaw is based on faulty authorization, it is exploitable by anyone who can reach the plugin endpoints, making the threat significant for exposed WordPress sites.
OpenCVE Enrichment