Impact
The CheckView WordPress plugin fails to enforce its authentication filter on REST API routes, allowing any request containing a plugin‑specific string to bypass nonce validation. This flaw lets an attacker cause an authenticated administrator to inadvertently create a new administrator account, giving full control of the site.
Affected Systems
All installations of the CheckView plugin for WordPress with a version lower than 2.3.2 are affected; any site using 2.3.1 or earlier is vulnerable.
Risk and Exploitability
The issue represents an authentication bypass (CWE‑285, CWE‑287). An attacker can exploit it by crafting a link that an administrator opens, triggering the bypass and creating a privileged account. Because the flaw can be accessed over the network, it is considered a remote vulnerability. The CVSS score of 8.8 indicates high severity, and the EPSS score of < 1% indicates a low but non-zero likelihood of exploitation. The flaw is not listed in the CISA KEV catalog, yet the risk to exposed WordPress installations remains significant if the plugin is in use.
OpenCVE Enrichment