Impact
A missing authorization flaw allows anyone who can reach the plugin’s AJAX endpoints to read or trigger actions that should be protected, effectively bypassing intended access controls. This vulnerability could expose internal data, logging information, or misuse the widget’s counters without permission. The issue originates from improperly configured access control security levels in the AJAX Hits Counter + Popular Posts Widget plugin.
Affected Systems
The vulnerability affects the WordPress plugin AJAX Hits Counter + Popular Posts Widget from the initial release through version 0.10.210305, all provided by the vendor kutsy.
Risk and Exploitability
The CVSS score of 5.4 indicates medium severity, while the EPSS score of less than 1% suggests a low probability of widespread exploitation at present. The vulnerability is not listed in the CISA KEV catalog. An attacker would need to send crafted requests to the plugin’s exposed AJAX endpoints, typically via any web browser or automated script, with no special authentication required. Because the flaw is in access control rather than code execution, the attack surface is broader but the potential impact remains within unauthorized access rather than full system compromise.
OpenCVE Enrichment