Impact
The CVE details a missing authorization flaw (CWE-862) in WPXPO WowAddons, which allows the exploitation of incorrectly configured access control security levels. The vulnerability arises when the plugin does not enforce appropriate role checks on certain administrative functions, meaning that users with access to the plugin’s admin interface could potentially perform actions that the system was intended to restrict.
Affected Systems
All WordPress installations that use WPXPO WowAddons 1.6.8 or earlier are affected. The vulnerability applies to every release of the WowAddons plugin distributed by WPXPO up to and including version 1.6.8, regardless of other WordPress security settings.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.5, indicating moderate severity. The EPSS score is below 1%, suggesting a low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the most likely attack vector involves reaching the plugin’s administrative interface over the web, although the CVE entry does not explicitly state whether authentication is required.
OpenCVE Enrichment