Impact
A missing authorization flaw in the Brandtoss WP Admin Audit plugin enables exploitation of incorrectly configured access control security levels. This bug can allow an attacker to perform actions that should be limited by the plugin’s intended access restrictions, potentially compromising administrative settings and data integrity. The vulnerability directly affects plugin versions up to 1.2.17.
Affected Systems
The issue is limited to installations of the Brandtoss WP Admin Audit WordPress plugin versions 1.2.17 and earlier. Users running these versions are at risk when the plugin is enabled on their sites.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Based on the nature of a broken access control flaw, it is inferred that attackers could potentially exploit this vulnerability remotely; however, the CVE does not provide explicit details about attack vector or prerequisites. The exploit path requires incorrect enforcement of access control within the plugin.
OpenCVE Enrichment