Impact
The vulnerability in the WP Delicious plugin is a missing authorization flaw that allows attackers or unauthenticated users to perform actions beyond their permitted access level. By exploiting incorrect access control settings, an attacker can view or modify content such as recipes, potentially compromising data integrity and confidentiality. This weakness is classified as CWE-862, indicating a missing authorization issue.
Affected Systems
The issue affects the WP Delicious plugin for WordPress versions up to and including 1.9.5. Any WordPress site that has the WP Delicious plugin installed and not yet updated beyond 1.9.5 is at risk.
Risk and Exploitability
The CVSS score of 5.3 places this vulnerability in the medium severity range, while an EPSS score of less than 1% indicates a low probability of exploitation at this time and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through normal web requests to the plugin’s endpoints, where an attacker with access to the site or a low-privilege role could send crafted requests to gain elevated permissions. No advanced prerequisites beyond valid web access are described, suggesting that surface-level exposure could be sufficient to exploit the flaw.
OpenCVE Enrichment