Impact
The vulnerability in the WP Search Analytics plugin is a missing authorization flaw that allows an attacker to bypass expected access controls. This flaw can lead to unauthorized retrieval or manipulation of analytics data stored by the plugin, potentially compromising the confidentiality and integrity of site statistics. The weakness is identified as CWE‑862, indicating inadequate enforcement of permission checks.
Affected Systems
The affected product is the WP Search Analytics plugin developed by Cornel Raiu for WordPress. Versions earlier than 1.5.0 are vulnerable. No specific cataloged versions beyond this boundary are listed.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity, while the EPSS score is not available, making the exact likelihood of exploitation uncertain. The plugin operates within a WordPress site, so the most likely attack vector is remote, via the web interface, exploiting incorrectly configured access levels. The vulnerability is not currently listed in the CISA KEV catalog.
OpenCVE Enrichment