Impact
This vulnerability is a missing authorization flaw that allows attackers to bypass configured access control in the WordPress PDF Poster plugin. An attacker could potentially modify or delete PDF posters and other privileged functions exposed by the plugin. The flaw stems from incorrectly configured security levels and is classified as CWE‑862. The impact is a potential loss of confidentiality, integrity, or availability of the content managed by the plugin.
Affected Systems
The affected product is the bPlugins PDF Poster plugin for WordPress. All releases up to and including version 2.4.1 are vulnerable. No other vendors or products are listed.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. EPSS score is not available, and the vulnerability is not listed in CISA KEV. The likely attack vector involves exploiting incorrect authorization checks within the plugin’s administrative endpoints, which could be accessed by users with inappropriate roles or by unauthenticated actors if the plugin exposes such endpoints. Because the weakness is a pure authorization flaw, the attack requires that the attacker reaches the WordPress site and that the plugin is present; no additional prerequisites are mentioned in the data.
OpenCVE Enrichment