Impact
A missing authorization check in the Designinvento DirectoryPress plugin allows attackers to access resources that should be protected, potentially viewing, editing, or deleting directory entries. This flaw is identified as CWE‑862 (Broken Access Control).
Affected Systems
Versions of the Designinvento DirectoryPress plugin up to and including 3.6.26 are vulnerable. The affected plugin release range is stated as n/a through 3.6.26 in the official description.
Risk and Exploitability
The recorded CVSS v3.1 base score of 5.4 indicates a moderate severity vulnerability, but the CVE data does not specify attack complexity or privileges required. EPSS indicates a very low likelihood (<1%) of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Attackers likely need to send crafted HTTP requests to exposed plugin endpoints, with no additional system privileges indicated by the CVE information.
OpenCVE Enrichment