Impact
The vulnerability is a missing authorization flaw in the Passionate Brains Add Expires Headers & Optimized Minify WordPress plugin, which permits attackers to invoke restricted endpoints without the proper access checks. By exploiting the incorrect configuration of access control security levels, an attacker can access or modify plugin settings and configuration data, potentially leading to configuration tampering or disclosure of sensitive information. This broken access control weakness is identified as CWE‑862.
Affected Systems
WordPress installations that have the Passionate Brains Add Expires Headers & Optimized Minify plugin installed with a version number 3.2.0 or earlier. All sites running these versions without the patch are vulnerable.
Risk and Exploitability
The CVSS score of 5.3 describes moderate severity, and the EPSS score is under 1%, indicating a very low current probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Nevertheless, because the flaw permits unrestricted access to privileged plugin functions, any user who can invoke the affected endpoint could read or alter data. The advisory recommends updating to the latest plugin release; no public workaround is available.
OpenCVE Enrichment