Impact
The plugin lacks proper authorization checks, resulting in a broken access control flaw that allows attackers to exploit incorrectly configured security levels. This flaw is classified as CWE‑862 and permits unauthorized users to gain access to restricted plugin functions or data, potentially compromising confidentiality and disrupt normal operation.
Affected Systems
Vendor and product: PluginRx:Broken Link Notifier. All versions from the earliest release through 1.3.5 are affected. Users running any 1.3.5 or earlier version are vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score of less than 1% suggests a very low likelihood of active exploitation, and the vulnerability is not listed in the CISA KEV catalog. The most probable attack vector is a web request to the plugin’s endpoints that lacks authentication checks, allowing an attacker to bypass normal access controls.
OpenCVE Enrichment