Impact
The plugin contains an unauthenticated broken access control flaw that lets an attacker perform administrative actions without proper credentials. This could lead to unauthorized content manipulation, data disclosure or modification, and potentially further compromise of the WordPress site.
Affected Systems
Stitch Express plugin for WordPress, versions 1.9.0 or older installed on any WordPress installation.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.5, indicating a high severity risk. EPSS information is not available and it is not listed in CISA’s KEV catalog, suggesting no widespread exploitation reports. Nevertheless, because the flaw permits unauthenticated users to bypass authorization controls, it can be leveraged from any network location that can reach the affected WordPress installation.
OpenCVE Enrichment