Impact
The Udimi Tools plugin for WordPress contains a missing capability check on its AJAX handlers that delete or create key configuration options. Because Subscriber-level users and above possess sufficient authentication authority, an attacker can trigger these endpoints to delete the six stored configuration options—API key, associated e‑mail address, and tracking‑script payload—or overwrite them with a malicious key. The result is loss of the site’s connection to its Udimi account and potential exposure to fraudulent activity.
Affected Systems
Any WordPress installation running webocoders’ Udimi Tools plugin version 3.2 or older is impacted. These sites use the plugin to integrate with Udimi’s traffic platform.
Risk and Exploitability
The CVSS rating of 6.5 indicates a moderate severity, and the EPSS score is not publicly available. The vulnerability is not listed in the CISA KEV catalog, yet it can be exploited by any authenticated user with Subscriber role or higher—a role that is common on many WordPress sites. Because the exploit requires only access to the admin interface and does not involve network-level attacks, the likelihood of exploitation remains moderate.
OpenCVE Enrichment