Impact
The vulnerability is a missing authorization flaw in The Post Grid plugin that permits attackers to bypass defined access control settings. Because the plugin fails to enforce proper authentication or role checks, an attacker could potentially perform actions that should be restricted to authorized users. The nature of the weakness is described by CWE-862, indicating a failure to check user permissions before allowing sensitive operations.
Affected Systems
All WordPress sites that run The Post Grid plugin version 7.9.2 or earlier are affected. The plugin, developed by Mamunur Rashid, is installed on sites using any WordPress build from the earliest unversioned releases through 7.9.2.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity impact. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves interacting with plugin‑specific URLs or administrative interfaces where the missing authorization check is applied. It is inferred that an attacker would need to reach these endpoints, potentially as an authenticated user or through publicly accessible pages, to exploit the flaw.
OpenCVE Enrichment