Impact
The Jeroen Peters Name Directory plugin for WordPress contains a missing authorization check that allows arbitrary shortcode execution. An attacker who can supply content to the plugin may inject and run shortcodes that execute PHP code on the host, potentially compromising the site’s confidentiality, integrity, and availability. This weakness is identified as CWE-862: Missing Permissions.
Affected Systems
The vulnerable product is the Name Directory plugin for WordPress, developed by Jeroen Peters. All releases from the earliest available version through 1.34.2 are affected. No vulnerability details are available for versions newer than 1.34.2.
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog. Because the flaw is a missing permissions check, it can likely be exploited by any user able to submit content to the plugin, possibly even unauthenticated users, as inferred from the lack of authentication controls.
OpenCVE Enrichment