Impact
The vulnerability is a missing authorization flaw in the WebAppick CTX Feed WordPress plugin that permits an attacker to bypass intended access controls. This flaw allows exploitation when the plugin’s access control settings are incorrectly configured, leading to unauthorized actions or access to sensitive information. The weakness corresponds to CWE‑862, indicating that insufficient privilege checks allow operations beyond the user’s intended permissions.
Affected Systems
Affects the WebAppick CTX Feed plugin for WordPress, published by WebAppick, in any release version 6.6.18 or earlier. No additional vendor/product or specific version patches are listed beyond the need for an upgrade.
Risk and Exploitability
The severity is moderate with a CVSS score of 5.3, and the exploitation likelihood is very low (EPSS <1%). It is not listed in the CISA KEV catalog. The overall risk is limited but still requires mitigation. Although the description does not specify the exact attack vector, it is inferred that an attacker could exploit the flaw through a web-based interface that interacts with the plugin, especially if authentication is weak or configuration is permissive.
OpenCVE Enrichment