Impact
The IATO MCP plugin suffers from a broken access control flaw that permits users to perform actions beyond their intended permissions. This weakness can allow an attacker to read, modify, or delete sensitive content or configuration settings within the WordPress site, compromising data integrity and confidentiality.
Affected Systems
Any WordPress installation that has the IATO MCP plugin version 1.11.0 or earlier is affected. The vulnerability applies to the plugin regardless of site size or usage pattern, so every site that has not upgraded to a newer release is at risk.
Risk and Exploitability
The CVSS score of 6.5 classifies this as a medium severity vulnerability, and because the EPSS score is not available, the likelihood of exploitation is uncertain but not negligible. The vulnerability is not listed in CISA's KEV catalog. The likely attack vector is via the web interface of a WordPress site, inferred from the description of a broken access control flaw. It is inferred that attackers may exploit the flaw by leveraging authenticated accounts with limited privileges to gain higher level access or by using unauthenticated users to manipulate plugin functions, as the description indicates a broken access control without further detail.
OpenCVE Enrichment