Impact
Unauthenticated users can exploit an access control flaw in the WordPress Content Control plugin, allowing them to view or modify content management functions that should be restricted to authenticated administrators. The vulnerability enables the attacker to bypass normal role checks and potentially alter or delete content, compromising the integrity and confidentiality of site data.
Affected Systems
This issue affects the Content Control plugin by Daniel Iser, any installed version up to and including 2.6.5. Sites running these versions are at risk until an updated release is applied.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation in the near term, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be unauthenticated web access to plugin endpoints, allowing attackers to interact with privileged functions without credentials.
OpenCVE Enrichment