Impact
The vulnerability is an unauthenticated broken authentication flaw in the miniOrange Discord Integration WordPress plugin version 2.2.4 or earlier. It permits an attacker to bypass normal authentication controls and potentially assume the identity of a privileged user, gaining unauthorized access to the WordPress site, its data, and connected Discord services. The weakness identified is CWE‑288, a failure to adequately verify credentials before allowing access rights.
Affected Systems
WordPress installations that have the miniOrange Discord Integration plugin at version 2.2.4 or older. No other products or versions are listed as affected, so any WordPress site using this plugin within the stated range is at risk.
Risk and Exploitability
The CVSS score of 8.1 marks this as high severity. EPSS is reported as less than 1%, indicating a low probability of widespread exploitation at present. The vulnerability is not listed in CISA KEV, but the lack of exploitation evidence does not reduce the risk. Based on the description, it is inferred that attackers would target sites with the vulnerable plugin by simply sending unauthenticated requests that trigger the broken authentication logic, bypassing standard security checks.
OpenCVE Enrichment