Impact
This vulnerability is an unauthenticated broken access control flaw in the Ad Invalid Click Protector plugin for WordPress that allows attackers to perform actions normally restricted to privileged users. The weakness falls under CWE‑862. The potential impact includes unauthorized modification of plugin settings or content that could be leveraged for further malicious activity.
Affected Systems
The affected product is the iSaumya Ad Invalid Click Protector (AICP) WordPress plugin, any installations using version 1.3.0 or earlier. End‑users running those versions are at risk.
Risk and Exploitability
The CVSS score for this issue is 6.5, indicating a moderate to high severity. EPSS score indicates a very low exploitation probability (<1%) and the vulnerability is not listed in the CISA KEV catalog. The flaw can be exploited by an unauthenticated attacker with access to the WordPress site, enabling them to execute privileged actions via the plugin’s broken access controls.
OpenCVE Enrichment