Impact
The vulnerability is a missing authorization flaw in the PublishPress Post Expirator WordPress plugin. It permits users to bypass the intended security levels and manipulate post expiration settings without proper authentication. This flaw can allow an attacker to change or delete expirations for any post, potentially disrupting scheduled content and affecting the integrity of the site’s publishing workflow.
Affected Systems
WordPress sites running the PublishPress Post Expirator plugin version 4.9.3 or earlier are affected. The vulnerability applies to all releases from the earliest available version up through 4.9.3.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate risk, and the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. The plugin’s web interface can be targeted remotely, so an attacker who can send authenticated or unauthenticated requests to the plugin’s endpoints may exploit the access control failure. Based on the description, it is inferred that the main attack vector is via the plugin’s administrative pages or REST API routes.
OpenCVE Enrichment