Impact
The vulnerability is a missing authorization check in DearFlip, which can allow an attacker to bypass configured access control and view protected content within a WordPress site. The flaw is classified as a broken access control weakness (CWE‑862). It does not enable code execution or a denial‑of‑service, but it permits disclosure of information that should be restricted to authorized users.
Affected Systems
All WordPress installations that use the DearFlip plugin version 2.4.27 or earlier are affected. The vulnerability applies to the DearHive DearFlip plugin across the WordPress ecosystem.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate impact severity. EPSS information is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited known exploitation. The likely attack vector is a web-based request to plugin endpoints that lack proper authorization checks. An attacker only needs to access these endpoints via a web browser or automated script; no authentication is required to reach the protected content.
OpenCVE Enrichment