Impact
The vulnerability is an authorization bypass that allows unauthenticated users to modify content through the publishTasks and unpublishTasks AJAX actions. By supplying arbitrary scenario IDs, an attacker can publish draft posts that were intended to remain hidden or unpublish posts that are already live. This can lead to exposure of sensitive content and disruption of the site’s normal publishing workflow. The weakness is a missing authorization check and is identified as CWE-862.
Affected Systems
The issue affects the Wupsales AI Copilot – Content Generator WordPress plugin, in all versions up to and including 1.4.12. The vulnerability is present in every installation of that plugin before the fix is applied. No other plugins or WordPress core components are implicated.
Risk and Exploitability
The CVSS score is 5.3, indicating a medium severity. The EPSS score of less than 1% shows a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. However, because the flaw can be triggered as AJAX endpoints, an attacker could exploit this remotely from any network that can reach the WordPress site. The consequence for the site owner is potential data leakage and disruption of content availability.
OpenCVE Enrichment