Impact
The vulnerability is an unauthenticated broken access control flaw that may let attackers bypass role checks within the Ebook Store plugin, potentially enabling them to view, modify, or delete content and sales records associated with the plugin. This could compromise the confidentiality and integrity of the store’s data, and affect the availability of e‑commerce functions on the site.
Affected Systems
WordPress websites that use the Ebook Store plugin version 6.19 or earlier. The impacted product is offered by the vendor motov.net and is commonly referred to as the WordPress Ebook Store Plugin. Users with sites running these versions should take note.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that any public endpoint that exposes plugin functionality could be a target. Once an attacker succeeds, they could perform actions within the scope of the plugin that should be restricted to authorized users.
OpenCVE Enrichment