Impact
The vulnerability is an unauthenticated broken authentication flaw in the IMPress for IDX Broker WordPress plugin. A remote attacker can bypass normal login controls and obtain privileged access to the WordPress admin interface. This enables the attacker to modify, delete, or add content, potentially exfiltrate data, or use the site for further malicious activity. The weakness is classified as CWE‑288, indicating that authentication mechanisms are improperly enforced.
Affected Systems
This issue affects the IMPress for IDX Broker plugin for WordPress, with all releases up to and including version 3.3.0 susceptible. The plugin is used by real‑estate agencies to embed IDX listings on WordPress sites, so sites running this plugin within the stated version range are affected.
Risk and Exploitability
The CVSS score is 6.5, which places the vulnerability in the medium severity range. No EPSS data is available, but the fact that authentication is broken means the attack can be performed without credentials, suggesting a relatively high likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, via a web request to the plugin’s authentication entry point.
OpenCVE Enrichment