Impact
Adminify WordPress plugin versions older than 4.2.10 do not enforce per‑user access checks on the results returned endpoint. This oversight permits a Contributor user to retrieve non‑public content that WordPress would normally hide, such as unpublished post titles, pending comment text, the plugin’s internal inventory of items, and other users’ account names. The flaw represents a low‑severity privacy breach governed by CWE‑200 and CWE‑285.
Affected Systems
WordPress installations that use Adminify with a version before 4.2.10 are affected, Contributor exploit via the vulnerable AJAX endpoint.
Risk and Exploitability
The CVSS score of 2.7 classifies the issue as low severity, yet it poses a confidentiality risk. The EPSS score of less than 1% indicates a very low likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an authenticated user with Contributor privileges to activate the global search feature, after which the plugin returns hidden search results to the attacker.
OpenCVE Enrichment