Impact
The vulnerability is a missing authorization flaw in the WP Wand AI content generation plugin for WordPress. Because the plugin fails to enforce proper access control, attackers can reach or modify protected content or other sensitive data. This flaw aligns with CWE‑862 and can let an unauthenticated user read or alter information that should be restricted, potentially compromising confidentiality and integrity for the site.
Affected Systems
The affected product is the WP Wand plugin from WP Grids. Versions from any release up to and including 1.3.07 are impacted. WordPress sites that have installed or enabled this plugin and have not applied a later version are at risk.
Risk and Exploitability
The CVSS score of 5.4 places the issue at a moderate risk level. The EPSS score is below 1 %, indicating a low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. The most likely attack vector is a remote web request: an attacker can craft HTTP inputs that bypass the missing authorization checks and access or modify content directly.
OpenCVE Enrichment