Impact
Missing authorization in the Israpil Textmetrics webtexttool plugin allows an attacker to exploit incorrectly configured access control security levels. This broken access control, identified as CWE‑862, gives unauthorized users the ability to use the plugin’s functionality without appropriate permissions, potentially leading to unauthorized modification or exposure of data within the WordPress site.
Affected Systems
The vulnerability affects the Israpil Textmetrics plugin for WordPress. Any installation using version 3.6.4 or earlier is susceptible. No specific sub‑version ranges are provided.
Risk and Exploitability
The CVSS score of 4.3 indicates a low severity impact. The EPSS score is reported as less than 1 % and the issue is not listed in CISA’s KEV catalog, suggesting limited exploitation activity to date. The input does not specify an attack vector; it is inferred that the flaw could be triggered through normal web requests to the WordPress site, but this cannot be confirmed from the available data. The low CVSS score and low exploit probability imply that while remediation is recommended, the risk to a well‑managed installation is comparatively modest.
OpenCVE Enrichment