Impact
Missing Authorization flaw in WPXPO PostX plugin allows an attacker to perform privileged actions that should be restricted, such as creating, editing, or deleting posts. The flaw arises from incorrectly configured access control security levels, resulting in a CWE‑862 vulnerability. The potential impact includes unauthorized data manipulation and possible escalation of privileges within the WordPress site.
Affected Systems
The vulnerability affects the WPXPO PostX plugin, also known as ultimate‑post, in all releases up to and including version 5.0.3. WordPress sites that have this plugin installed and have not applied newer updates are susceptible. No other products are listed as affected.
Risk and Exploitability
The CVSS base score of 7.5 classifies the issue as high severity, while the EPSS score of less than 1 % indicates a low probability of exploitation at this time. The vulnerability is not present in the CISA KEV catalog. The attack likely requires a compromised or legitimate user session, as the flaw involves missing authorization checks. An attacker who can authenticate (or exploit the plugin’s administrative endpoints) can elevate privileges or manipulate content without permission.
OpenCVE Enrichment