Impact
The vulnerability is a missing authorization flaw in the PixFort pixfort Core plugin that allows users to exploit incorrectly configured access control security levels. This flaw can enable an attacker to access, modify, or delete plugin settings or data without proper permissions, potentially leading to unauthorized data exposure or modification. The weakness is classified as CWE‑862, indicating an authorization error where the application fails to check whether the user has sufficient privileges to perform a request.
Affected Systems
The issue affects the PixFort pixfort Core WordPress plugin versions up to and including 3.2.22. Any site using these affected plugin versions is at risk.
Risk and Exploitability
With a CVSS score of 6.3, the vulnerability is of medium severity. EPSS indicates a very low probability of exploitation (<1%). The vulnerability is not currently reported in the CISA KEV catalog. The attack is likely web‑based, requiring access to the WordPress admin interface; users with limited or improperly scoped roles could potentially reach privileged plugin endpoints and exploit the missing authorization check. The impact is confined to plugin data rather than system-wide compromise, but can still lead to unauthorized data changes or disclosures.
OpenCVE Enrichment