Impact
The Total Upkeep plugin for WordPress contains a flaw that allows unauthenticated users to bypass normal access controls. An attacker can exploit this to perform actions normally reserved for authorized administrators, potentially adding, modifying, or deleting content, settings, or files. The weakness corresponds to CWE-862, broken access control, and is rated highly severe with a CVSS score of 8.2.
Affected Systems
The vulnerability applies to the WordPress Total Upkeep plugin developed by BoldGrid, specifically all releases up to and including version 1.17.2. Versions 1.17.3 and newer are reported to contain the fix.
Risk and Exploitability
With no EPSS value available, the exploitation probability is unclear from the data, but the high CVSS score indicates a significant risk. Based on the description, it is inferred that the attacker can trigger the vulnerable functionality by sending crafted HTTP requests to the plugin’s endpoints from any network location without authentication. The vulnerability is not listed in CISA's KEV data, suggesting that there have been no confirmed public demonstrations, but the nature of the flaw warrants immediate attention.
OpenCVE Enrichment