Impact
The vulnerability is a broken access control flaw that existed in Mediavine Control Panel plugin versions up to 2.10.10. It allows an attacker to invoke privileged plugin functions without proper authorization, potentially enabling unauthorized configuration changes, data exposure, or persistence. The weakness is classified as CWE‑862.
Affected Systems
WordPress sites that have the Mediavine Control Panel plugin version 2.10.10 or earlier installed. Administrators using these plugin versions are at risk. The plugin is typically distributed via WordPress.org and is used by sites that work with the Mediavine ad network.
Risk and Exploitability
The CVSS base score of 4.3 places the flaw in the moderate range. The EPSS score indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Based on the broken access control description, the likely attack vector is that an attacker who can authenticate to the WordPress site—either through credential compromise or social engineering—could trigger privileged plugin functions via the Mediavine Control Panel endpoints without proper capability checks. The CVE description does not specify the exact conditions or endpoints, so the precise risk profile beyond the severity and low exploit probability remains uncertain. Security teams should treat it as a low‑priority issue but still apply the fix when possible.
OpenCVE Enrichment