Impact
Broken access control in the WDS MCP Content Manager plugin allows an attacker to bypass normal permission checks defined by the plugin. The vulnerability is mapped to CWE-862 and can lead to unauthorized operations within the WordPress installation such as viewing, editing, or deleting content that the user is not supposed to handle. The effect is a compromise of confidentiality and integrity of site data, and could also provide a foothold for further lateral movement within the host if additional plugins or elevate privileges.
Affected Systems
WordPress sites that use the WDS MCP Content Manager plugin version 3.10.4 or earlier. The plugin is distributed under the vendor wallstrdev. No other versions are affected according to the current information.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate risk. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been widely exploited. The likely attack vector requires prior access to the WordPress admin interface, and the attacker could exploit the flaw by interacting with the plugin’s endpoints, ultimately gaining unauthorized control over content items without proper authorization checks.
OpenCVE Enrichment