Impact
The vulnerability is a missing authorization flaw that lets an unauthorized user interact with administrative functions of the Make My Trivia WordPress plugin. This weakness can allow a malicious actor to view, modify, or delete trivia content and settings, potentially leading to data exposure or inconsistent site behavior. The core weakness is a missing authorization check, identified as CWE‑862.
Affected Systems
Vulnerability affects the Netro Systems Make My Trivia plugin for WordPress, versions from the original release up to and including 1.1.0. No later versions were listed as affected.
Risk and Exploitability
The CVSS base score is 5.3, indicating moderate severity. An EPSS score of less than 1 % suggests a low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA known‑exploited catalog. The attack vector is likely local or network, requiring a user to interact with the plugin’s administrative interface; it does not provide remote code execution. An attacker with access to the site could exploit the missing authorization check to perform privileged actions.
OpenCVE Enrichment