Impact
Unauthenticated Broken Access Control in versions of the WPAdverts plugin up to 2.3.0 allows an attacker to perform privileged actions without needing to authenticate. An attacker could potentially edit, delete, or otherwise manipulate listings and user data, leading to data integrity compromise and potential defacement. This weakness is identified as CWE-862: Authorization Bypass Through Privileged Credentials.
Affected Systems
The vulnerability affects the WordPress WPAdverts plugin developed by Greg Winiarski. Any installation using version 2.3.0 or earlier is impacted; later versions are not affected.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, but the EPSS score of less than 1% suggests exploitation is currently unlikely. The flaw is not listed in CISA's KEV database, yet because it is unauthenticated, any visitor with network access to the WordPress site could exploit it by sending crafted requests to the plugin’s endpoints. The risk is that an attacker could compromise data integrity and potentially hijack the site’s content if left unpatched.
OpenCVE Enrichment