Impact
The vulnerability arises because the Finale Lite WordPress plugin before 2.21.0 performs no capability check on a specific AJAX action, allowing any authenticated user with Subscriber or higher role to retrieve detailed campaign configuration and scheduling data for an arbitrary post ID. An attacker who can authenticate will thus learn sensitive design and scheduling information, compromising confidentiality of campaign settings.
Affected Systems
Plugins: Finale Lite (WordPress) version below 2.21.0. Any WordPress installation that has this plugin active and includes users with Subscriber or higher roles. No specific vendor enumerated beyond the plugin name.
Risk and Exploitability
The flaw requires the user to be authenticated; it is not exploitable by an unauthenticated visitor. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, indicating no known public exploitation yet. The lack of a capability check makes the scenario highly exploitable if an attacker compromises a user account. The CVSS score is 4.3, which indicates a moderate severity for information disclosure.
OpenCVE Enrichment