Impact
A missing authorization flaw in the WordPress WPAdverts plugin enables an attacker to perform actions that should be restricted. The vulnerability allows exploitation of incorrectly configured access control security levels, potentially permitting the creation, modification or deletion of advert entries and other administrative functions that normally require higher privileges.
Affected Systems
The issue impacts the WPAdverts plugin developed by Greg Winiarski. All installed versions up to and including 2.3.0 are affected. The product is a WordPress extension that manages classified ads on a site.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, but the EPSS score of less than 1% suggests that real‑world exploitation is unlikely at present. The vulnerability is not listed in the CISA KEV catalog. The probable attack vector is a remote web‑based exploit, inferred from the plugin’s nature and the lack of a local requirement mentioned in the description. If an attacker can reach the plugin’s administrative interface or trigger its functionality, the missing access control could be leveraged to obtain unauthorized data manipulation rights.
OpenCVE Enrichment