Impact
Missing authorization allows attackers to manipulate or access data that should be restricted. The vulnerability arises from improperly configured access controls within the FlexTable plugin, enabling users without proper permissions to view or edit table content. This breach can lead to data leakage or unauthorized modifications, compromising the confidentiality and integrity of site content.
Affected Systems
WordPress sites running the FlexTable plugin up to and including version 3.24.0 are impacted, as the flaw exists in all versions from the earliest releases through 3.24.0.
Risk and Exploitability
The CVSS score of 4.3 signals moderate severity, yet no EPSS score is available, so the exact exploitation likelihood is uncertain. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is through interaction with the plugin’s administrative interface, allowing an attacker with access to the site to exploit the broken access control to gain privileges beyond those intended.
OpenCVE Enrichment