Impact
A missing authorization flaw in the WordPress plugin The Moneytizer allows privileged actions to be performed without proper verification, resulting in a breach of access control. The vulnerability is classified as CWE-862 (Broken Access Control).
Affected Systems
Any WordPress installation that has lvaudore’s The Moneytizer plugin installed with a version up to and including 10.0.10 is affected. If the site uses any earlier or later version, it is not known to be vulnerable.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity, while an EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. The CVE description does not specify the exact exploitation method, but it is inferred that an attacker would need to send specially crafted HTTP requests to the plugin’s endpoints, potentially while authenticated to the WordPress site, to bypass the missing access checks and perform unauthorized actions.
OpenCVE Enrichment