Impact
The vulnerability is a missing authorization flaw that allows an attacker to perform actions within the TOP Table Of Contents plugin that should be restricted. This breaks the intended access control, enabling an attacker to modify plugin settings or other privileged data. The weakness is identified as CWE-862 (Missing Authorization).
Affected Systems
WordPress sites that run the WP Messiah TOP Table Of Contents plugin version 1.3.31 or earlier are affected. All releases up to 1.3.31, including any prior versions, are susceptible. Site administrators who rely on this plugin for table of contents management may be at risk.
Risk and Exploitability
The CVSS score of 4.3 indicates a medium impact, and the EPSS score of less than 1% suggests that, at the time of analysis, exploitation is unlikely to be widespread. The vulnerability is not listed in the KEV catalog. The likely attack vector is through the normal web interface that the plugin exposes; an attacker with access to the site’s front‑end or who can send crafted requests may exploit the missing authorization check. No additional conditions such as local privilege escalation or privileged user context are specified in the available data.
OpenCVE Enrichment