Impact
The vulnerability is a broken access control flaw that allows an attacker to bypass authorization checks in the Endless Posts Navigation WordPress plugin. This weakness, identified as CWE‑862, permits users without proper privileges to view or modify navigation configuration, potentially exposing or altering site content. The impact is primarily unauthorized access to administrative functions of the plugin, which could enable further exploitation if combined with other WordPress weaknesses.
Affected Systems
Vendors and products affected include the Endless Posts Navigation plugin developed by Fahad Mahmood. All installations using version 2.2.9 or earlier are susceptible. The issue is documented for all releases from the earliest version up through 2.2.9.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of active exploitation at present. The vulnerability is not listed in the KEV catalog. Though the attack vector is not explicitly stated in the official data, the likely path is a remote web-based request to the plugin’s configuration endpoints due to its WordPress context. An attacker with network access to the site could exploit the flaw without needing additional credentials, leading to unauthorized configuration changes or exposure of sensitive navigation data.
OpenCVE Enrichment