Impact
This vulnerability is a missing authorization flaw that permits an attacker to modify or view the Anything Order by Terms plugin configuration without proper checks. The flaw directly undermines the plugin’s intended access restrictions, enabling changes that a user should not be allowed to make. The vulnerability is categorized as CWE‑862, Missing Authorization.
Affected Systems
The flaw affects briarinc Anything Order by Terms plugin versions 1.4.0 and earlier installed in WordPress sites. Any installation that includes this plugin is subject to the risk.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, while the EPSS score of less than 1 percent suggests a very low current likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. At a minimum, an attacker must have authenticated access to the WordPress admin interface and the ability to reach the plugin settings page; once they do, they can alter configuration values that are not properly protected. Despite the low exploitation probability, the potential for unauthorized configuration changes warrants prompt remediation.
OpenCVE Enrichment