Impact
The vulnerability is an Authorization Bypass Through User‑Controlled Key that permits attackers to exploit incorrectly configured access control security levels in the Authorsy plugin. It enables unauthorized users to access or manipulate protected objects, effectively allowing privilege escalation or data tampering. The underlying weakness is identified as IDOR, categorized as CWE‑639.
Affected Systems
Authorsy plugin from themeplugs is affected in all released versions up to and including 1.0.6. The vulnerability applies across all installations of the plugin that have not yet been updated beyond this version.
Risk and Exploitability
The CVSS Base score of 7.5 indicates high severity. The EPSS score of less than 1% suggests a very low probability of exploitation at the present time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack vector is not explicitly documented in the description, but it is inferred that the flaw can be triggered by manipulating web requests that specify user‑controlled keys, typically via crafted URLs or API calls.
OpenCVE Enrichment