Impact
The vulnerability in the Deepak Anand WP Dummy Content Generator plugin results from missing authorization checks, allowing an attacker to bypass security levels and execute privileged actions such as creating, editing, or deleting content. As a result, unauthorized parties can alter the integrity of a WordPress site, compromising the confidentiality and consistency of published material. The flaw aligns with CWE‑862, indicating a breakdown in proper access control enforcement.
Affected Systems
WordPress sites running the WP Dummy Content Generator plugin by Deepak Anand, specifically versions from the initial release up to and including 4.0.0. Any installation of this plugin within that version range is susceptible to the access‑control failure.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate impact, and no EPSS data is available, so the market exploitation probability cannot be precisely quantified. The vulnerability is not listed in CISA KEV, suggesting no widespread exploitation has been documented yet. Exploitation would likely require access to the WordPress admin interface, but the absence of authorisation checks could allow any authenticated user—or potentially any visitor if the plugin’s endpoints are exposed—to manipulate content. Attackers could exploit this flaw to inject malicious content, deface the site, or alter existing posts.
OpenCVE Enrichment