Impact
The vulnerability is an unauthenticated broken access control flaw that allows an attacker to bypass WordPress permissions when interacting with the plugin’s post listing functionality. This flaw permits the attacker to view, edit, or delete content that is normally restricted to privileged users, potentially leading to data exposure or content tampering.
Affected Systems
WordPress sites that have the Advanced Posts Listing – Show Post List Easily plugin version 1.0.8 or earlier installed and activated. The plugin is developed by Flipper Code and is used in any WordPress installation that includes it.
Risk and Exploitability
The CVSS score of 7.5 indicates high risk. Although there is no EPSS data, the vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploits yet. Attackers can exploit the flaw by sending crafted requests to the plugin’s endpoints without authentication, immediately accessing restricted resources. The lack of additional prerequisites makes exploitation likely for affected sites.
OpenCVE Enrichment