Impact
WordPress BerqWP plugin versions up to 4.1.15 contain an unauthenticated broken access control flaw. An attacker can access restricted management interfaces or pretend to be an authorized user, which can lead to disclosure, modification, or deletion of website content. The weakness centers on the plugin’s failure to enforce proper authentication checks, categorized as CWE-862.
Affected Systems
Any WordPress instance running the BerqWP plugin version 4.1.15 or earlier is affected. The plugin is distributed under the BerqWP brand and appears in WordPress plugin installations without additional application customers or custom versions noted.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity; the EPSS score is not available, and the vulnerability is not listed in CISA KEV. The likely attack vector is unauthenticated access to plugin management functions, with no known exploits published at this time. The risk is moderate, but the lack of known CVE exploitation mitigates immediate concern, though proactive remediation is advised.
OpenCVE Enrichment