Impact
A missing authorization check in the WordPress WpXmas‑Snow plugin allows attackers to bypass access controls and perform operations normally reserved for privileged users. The vulnerability, classified as CWE‑862, enables browsing, modifying or deleting content and changing plugin settings, effectively granting unauthorized administrative capabilities.
Affected Systems
The flaw affects all installations of WpXmas‑Snow by Pankaj Kumar from the initial release up to version 1.1. Any WordPress site that has one of these versions deployed is at risk.
Risk and Exploitability
The CVSS score of 5.3 reflects moderate severity, while the EPSS score of less than 1% indicates that exploitation is currently rare. The vulnerability is not listed in the CISA KEV catalog, further suggesting limited public exploitation. Based on the description, the attack vector is likely the web interface where a standard authenticated user accesses a protected endpoint without proper authorization. The impact is confined to the compromised WordPress installation but can be significant if sensitive content or configuration is present.
OpenCVE Enrichment