Impact
The vulnerability is a classic unauthenticated broken access control flaw that allows an attacker to read legal texts without any authorization. The weakness is identified as a missing authorization check (CWE‑862), which could let an attacker view or download confidential legal documents stored by the plugin. The impact is the potential exposure of proprietary legal information, with moderate severity as reflected by the CVSS score of 6.5.
Affected Systems
Vulnerable products are the Legal Text Connector of the IT‑Recht Kanzlei WordPress plugin, versions up to and including 1.0.13. The plugin is typically used on websites that host legal documents such as privacy policies or terms of service. Only these versions are affected; any installation running 1.0.14 or newer is considered fixed.
Risk and Exploitability
The high value of the CVSS score indicates that the vulnerability could be successfully exploited by an unauthenticated user to gain access to restricted content. The EPSS score is not available, so the current exploitation probability is unknown, but the lack of protection against unauthenticated access means that a determined attacker could exploit it immediately. The vulnerability is not listed in the CISA KEV catalog, implying that a zero‑day or widespread exploitation has not yet been observed, yet the flaw remains exploitable in the wild.
OpenCVE Enrichment