Impact
WordPress Easy Post Submission plugin versions up to and including 2.4.0 contain a missing authorization flaw that allows any visitor with access to the submission form to create posts without permission, potentially enabling spam, defacement, or deceptive content; the weakness maps to CWE‑862, indicating improper authorization checks.
Affected Systems
Applicable to all releases of ThemeRuby Easy Post Submission (Easy Post Submission) from the earliest available version up to and including 2.4.0; all environments running these versions are impacted.
Risk and Exploitability
With a CVSS score of 7.5, the vulnerability is considered high severity; however, the EPSS score is below 1%, indicating a low likelihood of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw by submitting content through the plugin’s web interface without authentication, making the attack vector primarily web‑based and reliant on the lack of enforced access control.
OpenCVE Enrichment