Impact
This vulnerability is a missing authorization flaw that allows attackers to bypass the plugin’s access control and use functionality intended for privileged users. The attacker can create, edit, or delete bulk landing pages and potentially expose sensitive configuration or content. The flaw is categorized under CWE‑862, indicating a broken access control weakness that can lead to privilege escalation.
Affected Systems
The affected product is Bulk Landing Page Creator for WordPress LPagery developed by niklaslindemann. All versions from the earliest available through 2.4.9 are impacted.
Risk and Exploitability
EPSS indicates a very low exploitation probability (below 1%), and the vulnerability is not listed in CISA’s KEV catalog. However, the potential impact is high, as the flaw permits full use of privileged plugin functions. Likely attack vectors involve the plugin’s administrative endpoints which can be accessed by authenticated users, but if the attacker can carefully craft a request they might exploit the missing authorization to introduce content or gain elevated privileges. The overall risk is moderate: low likelihood but significant consequences if exploitation occurs.
OpenCVE Enrichment