Impact
The vulnerability is a broken access control flaw in BdThemes Ultimate Post Kit that allows an attacker to perform privileged operations such as creating, editing, or deleting posts and comments without proper authorization. This flaw permits an attacker to tamper with website content, potentially undermining the integrity of published material and the trust of site visitors.
Affected Systems
WordPress sites that have the BdThemes Ultimate Post Kit plugin installed in any version through 4.5.5 are vulnerable. The issue is linked to the plugin’s default configuration and may affect any user who can access the plugin’s administrative interface.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, reflecting moderate impact on integrity and potential availability. The EPSS score is not available, so the likelihood of exploitation cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is internal or user‑based; based on the description, it is inferred that any authenticated user with insufficient privileges may be able to exercise the broken permissions, or that configuration errors could expose the privileged functions to all users.
OpenCVE Enrichment