Impact
The vulnerability is a Subscriber Broken Access Control flaw present in Ditty plugin versions 3.1.67 and earlier, which allows users with the subscriber role to perform actions that should be privileged. This flaw is a direct authorization bypass, potentially granting unauthorized users access to protected data or functions within the WordPress site.
Affected Systems
WordPress sites that have the Ditty plugin installed at version 3.1.67 or earlier, developed by metaphorcreations. The affected product is the Ditty plugin, and any installation running these versions is in scope.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score is not available, so the exact likelihood of exploitation cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. The attack vector is likely local or network from a user who has authenticated to the site with a subscriber role; the attacker does not need privileged access beyond the subscriber level, which is also a common role for many sites. Because the flaw arises from broken authorization checks, an attacker can obtain unauthorized access to the plugin’s privileged functions through normal site interactions.
OpenCVE Enrichment