Impact
The vulnerability is a missing authorization flaw in the Nelio AB Testing plugin. Incorrectly configured access control allows an attacker to invoke plugin endpoints without proper authentication, resulting in the exposure of sensitive data stored by the plugin. This issue is identified as an access-control weakness (CWE-862).
Affected Systems
WordPress sites using Nelio Software’s Nelio AB Testing plugin with versions up to and including 8.2.8 are affected. The flaw applies regardless of the specific administrator configuration because the plugin fails to enforce the intended security levels.
Risk and Exploitability
The exploitation path is straightforward: an unauthenticated user can call API routes or view management screens that should be restricted, leading to data leakage. The EPSS score is <1%, but the absence of authentication checks makes the vulnerability theoretically easy to exploit. The vulnerability is not currently listed in the CISA KEV catalog, yet the potential for serious data exposure warrants a moderate risk assessment. Administrators should treat this as a critical issue until a patch is applied.
OpenCVE Enrichment