Impact
Unauthenticated broken authentication allows an attacker to gain access to privileged function of the Ezoic plugin for WordPress without proper credentials. The flaw is categorized as CWE‑288 and enables unauthorized users to assume administrative privileges within the WordPress environment, potentially exposing sensitive data or enabling further attacks.
Affected Systems
All installations of the Ezoic plugin for WordPress version 2.22.11 and earlier are affected. The product, sold by Ezoic, is deployed in WordPress sites that use this plugin.
Risk and Exploitability
The CVSS score is 7.5, indicating high severity. The EPSS score is not available, so the probability of exploitation cannot be quantified precisely. The vulnerability is not listed in the CISA KEV directory. Likely exploitation requires remote interaction with the WordPress site hosting the vulnerable plugin, and an attacker can achieve privileged access once the authentication bypass is performed.
OpenCVE Enrichment