Impact
This vulnerability arises from broken access control in the WordPress plugin Advanced Custom Fields: Font Awesome Field versions 6.1.1 and earlier, allowing an attacker to bypass authorization checks. As a result, an unauthorized user could access or modify sensitive plugin settings or data. The weakness is identified as CWE-862, indicating that the code does not properly enforce access controls. Based on the description, it is inferred that the attacker would need to interact with the plugin’s administrative interface or any endpoint that permits configuration changes.
Affected Systems
The affected product is the Advanced Custom Fields: Font Awesome Field plugin for WordPress, developed by Justin Kruit. Versions up to and including 6.1.1 are impacted. WordPress sites that have this plugin installed without updating to a newer version are susceptible.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate risk. EPSS is not available, so the current probability of exploitation is unknown. The vulnerability is not listed in CISA’s KEV catalog. Attackers would need to exploit the broken access control; based on the description it is inferred that the vulnerability can be leveraged by users who can interact with the plugin’s administrative interface, potentially including authenticated users with low privileges. Based on the description, it is inferred that the attack vector involves interacting with the plugin's administrative interface, possibly via authenticated users with limited privileges. Absence of a publicly known exploit reduces immediate risk, but the lack of proper enforcement of access rights remains a concern.
OpenCVE Enrichment