Impact
The vulnerability is a missing authorization flaw in the WordPress plugin that permits attackers to access actions that should be restricted to privileged users. Without proper access checks, an attacker could solicit the plugin’s endpoints to view or alter configuration data, leading to potential information disclosure or unauthorized changes. This represents a standard broken access control weakness, classified as CWE‑862.
Affected Systems
WordPress installations that have the Passionate Brains Add Expires Headers & Optimized Minify plugin version 3.1.0 or earlier. All sites running these versions without the patch are vulnerable.
Risk and Exploitability
The CVSS score of 5.3 describes moderate severity, and the EPSS score is under 1%, indicating a very low current probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Nevertheless, because the flaw permits unrestricted access to privileged plugin functions, any user who can invoke the affected endpoint could read or alter data. The advisory recommends updating to the latest plugin release; no public workaround is available.
OpenCVE Enrichment