Impact
The PublishPress Permissions plugin contains an unauthenticated Insecure Direct Object Reference that allows any web visitor to request arbitrary permission data by guessing or constructing direct URLs. This flaw is a classic IDOR vulnerability (CWE‑639). If exploited, an attacker can read or modify the permissions associated with posts, pages, or other content, thereby compromising the confidentiality and integrity of site content settings.
Affected Systems
The vulnerability affects the WordPress plugin PublishPress Permissions for all releases up to and including version 4.8.3. No other variants or related products are listed, and the issue does not span to higher versions such as 4.8.4 and later.
Risk and Exploitability
The CVSS score of 5.3 places the flaw at moderate severity, and the vulnerability is not included in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires no credentials; any user capable of crafting or guessing an object URL can potentially retrieve permission data. The EPSS score is not available, so a quantitative assessment of exploitation likelihood cannot be provided, but the nature of the IDOR suggests it is readily exploitable by anyone who can discover the URL pattern. The attack vector is inferred from the description of the flaw as an unauthenticated direct object reference.
OpenCVE Enrichment