Impact
The Restrict Content plugin for WordPress suffers from a missing authorization control, allowing an attacker to gain privileges beyond what is appropriate. This flaw permits bypassing the intended security levels and accessing protected content or administrative functions, potentially exposing sensitive data or compromising site integrity.
Affected Systems
Any WordPress site that has the Restrict Content plugin installed in version 3.2.22 or earlier is affected. This includes installations from StellarWP that do not upgrade to at least version 3.2.23.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. Exploitation is feasible via web requests to the plugin’s endpoints, though the exact attack vector is inferred to be remote through the publicly accessible WordPress interface, as the description does not detail local prerequisites. No EPSS score is available, so the probability of exploitation cannot be quantified, and the vulnerability is not recorded in the CISA KEV catalog.
OpenCVE Enrichment