Impact
A WordPress plugin, Stitch Express version 1.9.0 or older, contains an unauthenticated broken access control flaw that allows an attacker to execute administrative operations without valid credentials. Such actions could enable content manipulation, unauthorized data disclosure or tampering, and in turn facilitate further compromise of the entire WordPress site.
Affected Systems
Stitch Express plugin for WordPress, any installation running version 1.9.0 or earlier is affected.
Risk and Exploitability
The issue has a CVSS score of 7.5, indicating a high severity potential. EPSS score is below 1%, suggesting a very low exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is network-based, as an unauthenticated user can reach the affected WordPress site and exploit the flaw from any location that can access the plugin’s endpoints.
OpenCVE Enrichment