Impact
The vulnerability is an unauthenticated broken access control flaw in the Graphina WordPress plugin. This weakness allows an attacker who does not possess a valid user account to perform privileged actions, such as modifying charts and graph data or accessing administrative interfaces. The potential consequences include unauthorized data manipulation or exposure of sensitive content. Without authentication, the attacker can easily exploit the flaw by sending crafted HTTP requests to the plugin’s endpoints.
Affected Systems
The affected product is the Graphina plugin by Iqonic Design, versions 3.1.12 and earlier. Any WordPress site that has these versions of the plugin installed is susceptible to the flaw.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity. The EPSS score of less than 1% signals that the probability of exploitation is very low, and the vulnerability is not currently listed in the CISA KEV catalog. The most likely attack vector involves an attacker sending specially crafted HTTP requests to the plugin’s access endpoints, a maneuver that can be performed without authenticating to the site. Successful exploitation would grant the attacker unauthorized control over the plugin’s features and potentially the hosting webpage’s content.
OpenCVE Enrichment