Impact
The vulnerability is a broken access control flaw affecting the subscriber role in the AWS S3 for WordPress Plugin – Upcasted. An adversary with subscriber permissions can bypass the plugin’s intended restrictions, potentially accessing, modifying, or deleting objects stored in an Amazon S3 bucket linked to the site. The flaw could compromise the confidentiality and integrity of media assets.
Affected Systems
All installations of the Upcasted AWS S3 for WordPress Plugin – Upcasted version 3.1.0 or earlier. The plugin is a WordPress extension provided by Upcasted that offloads media to Amazon S3.
Risk and Exploitability
The CVSS base score of 6.3 indicates moderate severity, and the vulnerability is not listed in the CISA KEV catalog. EPSS data is not available, so the likelihood of public exploitation cannot be quantified. Based on the description, the likely attack vector is leveraging an existing subscriber account to escape role restrictions; if an attacker controls such an account or subverts role assignment, they can directly read or write arbitrary S3 objects, leading to data disclosure or loss.
OpenCVE Enrichment