Impact
The Petitioner plugin contains a missing authorization vulnerability that allows users to perform actions beyond their privilege level; an attacker with a lower role can exploit incorrectly configured access control and manipulate content or settings, compromising the integrity of the site and potentially exposing sensitive information.
Affected Systems
All installations of the Anton Voytenko Petitioner WordPress plugin from the initial release up to and including version 0.7.3 are affected; any WordPress site using these versions is at risk.
Risk and Exploitability
With a CVSS score of 6.5 the vulnerability is of moderate severity, and an EPSS score of less than 1 % indicates a low likelihood of exploitation in the wild; it is not listed in the CISA KEV catalog. The attack likely occurs over the web interface and requires an authenticated user whose privileges are incorrectly trusted by the plugin, allowing escalation to higher‑level actions.
OpenCVE Enrichment