Impact
Insecure Direct Object References (IDOR) exist in the Cooked WordPress plugin versions 1.16.0 and earlier. The vulnerability allows an attacker to manipulate requests to the plugin’s endpoints, potentially exposing or modifying data that belongs to other users. This can lead to unauthorized information disclosure or modification, as indicated by the CWE-639 weakness.
Affected Systems
The affected product is the Cooked plugin from Gora Tech. All installations running version 1.16.0 or earlier are impacted. The official recommendation is to upgrade to version 1.16.1 or later, which eliminates the IDOR flaw.
Risk and Exploitability
The CVSS score is 5.4, indicating a medium severity impact. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, which suggests that the exploitation likelihood is currently uncertain. The attack vector is inferred to be remote, via manipulated HTTP requests to the plugin’s API endpoints, and typically requires a valid authenticated session with sufficient privileges to access or modify the targeted objects. Due to the lack of public exploits, the current immediate risk is moderate, but the vulnerability could be leveraged in a targeted attack to compromise user data.
OpenCVE Enrichment