Impact
The vulnerability in the Articles Anywhere and Modules Anywhere Joomla extensions allows a content author to use ignore flags or property overrides so that restricted or unpublished articles and modules are rendered publicly. This flaw bypasses Joomla’s built‑in access restrictions, enabling confidential or unpublished material to be displayed to visitors who normally lack the required permissions. It is inferred that the attacker would need to be an authenticated content author with the ability to apply these overrides to create the bypass.
Affected Systems
Joomla content management systems that have the Articles Anywhere or Modules Anywhere extensions from regularlabs.com installed. All versions of these extensions that have not received the vendor’s patch are affected, irrespective of the underlying Joomla core version.
Risk and Exploitability
The CVSS score of 9.1 indicates a high severity vulnerability, while the EPSS score of less than 1% suggests a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated content author to craft ignore flags or property overrides; once created, any visitor who accesses the affected content rendering endpoint can view the previously restricted material. No additional prerequisites are required beyond the authoring role. It is inferred that the attack vector would involve an eligible user leveraging rendering options to expose the content to a broader audience.
OpenCVE Enrichment