Impact
The Proptech Plugin Apimo Connector contains a missing authorization flaw that allows users to exploit incorrectly configured access control security levels. The vulnerability can be used to view or manipulate real‑estate data managed by the plugin without proper privileges. It is identified as CWE‑862 and has a CVSS base score of 5.3, indicating moderate severity.
Affected Systems
WordPress sites that have the Proptech Plugin Apimo Connector activated and running any version up to and including 2.6.5.2 are vulnerable. Because the plugin integrates directly into the WordPress admin area, any site that exposes the plugin’s admin pages is at risk if the access controls are misconfigured.
Risk and Exploitability
The CVSS score of 5.3 signifies moderate impact, while the EPSS score of less than 1% indicates that real‑world exploitation is currently uncommon. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a web‑based request to protected plugin pages, potentially requiring a low‑privilege authenticated account, but exploitation could be easier if the plugin’s access controls are incorrectly set.
OpenCVE Enrichment