Impact
The vulnerability is an authorization flaw that permits users without proper privileges to access restricted sections of the Proptech Plugin Apimo Connector. This can lead to unauthorized viewing or manipulation of real‑estate data managed by the plugin, potentially compromising confidentiality, integrity, and availability of host sites. The weakness is identified as CWE‑862.
Affected Systems
This flaw exists in all releases of the Apimo Connector plugin up to and including version 2.6.5.1. Systems running WordPress with the Proptech Plugin Apimo Connector before that version are vulnerable. Because the plugin integrates directly into the WordPress admin area, any WordPress installation that has the plugin activated and is reachable over the network or internal network may be affected.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity. The EPSS score is below 1 %, suggesting that real‑world exploitation is currently rare. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a web‑based request sent to protected plugin pages, possibly requiring authentication with a low‑privilege account; however, exploitation can be easier if access controls are misconfigured. The problem is exploitable as long as the plugin is deployed and the site is exposed, making timely remediation important.
OpenCVE Enrichment