Impact
Based on the description, the broken access control flaw (CWE-862) allows any visitor to the plugin’s administrative pages to create, modify, or delete plugin data. Because authentication is not required, it is inferred that an attacker can impersonate a privileged user within the plugin and alter its configuration or contents, potentially leading to unauthorized content publication or further site compromise.
Affected Systems
WordPress sites that have the Arraytics Booktics plugin in version 1.0.24 or earlier installed. The description does not state a dependency on site configuration, but it is inferred that the vulnerability therefore applies to all such installations where the plugin’s admin endpoints are reachable.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity; the EPSS score of less than 1% shows a very low probability of exploitation, and the issue is not listed in CISA KEV. It is inferred that attackers can exploit the flaw remotely via the web interface, and no prior authentication is required. If the plugin is exposed to the internet, it is inferred that an attacker can gain unintended administrative control over the plugin’s data.
OpenCVE Enrichment