Impact
Unauthenticated users can view or download sensitive information stored by the WordPress Ebook Store plugin in versions up to 6.19. The flaw lies in missing authorization checks when accessing protected data, allowing attackers to read private content without credentials. This results in a compromise of confidentiality that can affect users and store owners alike. This is a CWE‑862 Missing Authorization weakness.
Affected Systems
WordPress sites running the Ebook Store plugin from motov.net, versions 6.19 or earlier, are affected. Any installation that has not been updated to at least version 6.20 will remain vulnerable.
Risk and Exploitability
The CVSS score of 7.5 classifies this issue as High severity. Because authentication is not required, the attack vector is easily reachable from the outside; exploitation does not require special conditions or elevated privileges. The EPSS score is < 1%, indicating a very low but non-zero exploitation probability, and the flaw is not cataloged in CISA KEV, but the lack of authentication combined with a high base score indicates that the risk of exploitation remains significant until the plug‑in is upgraded. This is a CWE‑862 Missing Authorization issue.
OpenCVE Enrichment