Impact
The PublishPress Series plugin allows an attacker to bypass authorization controls by exploiting an improperly configured key in the plugin’s access control system. This abuse of an unchecked user‑controlled parameter lets a user read or modify series content that they normally should not access, effectively creating an Insecure Direct Object Reference. The flaw is classified as CWE‑639 and can lead to unauthorized viewing or editing of sensitive data within the WordPress site.
Affected Systems
PublishPress:PublishPress Series plugin, all releases from the initial version through 3.1.3, including every build that did not yet receive the 3.1.4 fix. This includes any WordPress installation that has the plugin enabled and the default or incorrect permission configurations in place.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate impact. EPSS is not available, and the vulnerability is not included in the CISA KEV catalog, implying it is not currently a known exploited vulnerability. The attack vector is the web application, and the attacker would likely need a user context or exploit a mis‑configured role that grants read/write access to series content. Because the flaw stems from a mis‑configured authorization key, the exploit is relatively low effort once the relevant permissions are discovered, but it requires knowledge of the site’s role and permission structure.
OpenCVE Enrichment