Impact
The vulnerability allows a user to access or modify subscriber data by manipulating a URL or request parameter, bypassing the intended access control. An attacker who can guess or enumerate subscriber identifiers can read or alter data that should be restricted to authorized editors or administrators. The weakness stems from improper authorization checks (CWE-639).
Affected Systems
The issue exists in the WordPress Modal Survey plugin version 2.0.2.2.3 and earlier. Logging in as a regular subscriber or posting a crafted request can trigger the IDOR. No other products or versions are reported as affected.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. Because the EPSS score is unavailable, the likelihood of immediate exploitation cannot be quantified, but the vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is an internal user or an authenticated visitor who can manipulate request parameters to access other subscribers’ data.
OpenCVE Enrichment