Impact
The Codemenschen Gift Vouchers plugin contains a missing authorization flaw that may allow an attacker to exploit incorrectly configured access control security levels, potentially enabling unauthorized access to voucher data.
Affected Systems
WordPress installations that use the Codemenschen Gift Vouchers plugin version 4.6.9 or earlier are vulnerable. Sites that have not upgraded beyond 4.6.9 may be impacted, irrespective of whether other security measures are in place.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity while the EPSS score of less than 1% shows a low public exploitation probability. The vulnerability is described as a missing authorization flaw that could allow exploitation of incorrectly configured access control security levels. The CVE does not provide a specific attack vector, but based on the description it is inferred that misconfiguration could enable unauthorized access. No additional prerequisites are documented.
OpenCVE Enrichment