Impact
The MPCX Lightbox plugin is missing an authorization check on a specific AJAX endpoint, permitting any visitor without credentials to invoke the action. This flaw enables retrieval of the title, content, or excerpt of any post, regardless of its visibility status. As the affected content may be private, draft, pending, trashed, or password‑protected, the potential impact is the unintended disclosure of confidential or unpublished information, compromising data confidentiality but not necessarily integrity or availability.
Affected Systems
WordPress sites that have the MPCX Lightbox plugin installed with versions 1.2.2 through 1.2.5 are affected. The vulnerability is specific to the plugin’s AJAX handling of post content, not to WordPress itself or other plugins.
Risk and Exploitability
The CVSS score of 3.7 indicates a low‑moderate severity vulnerability. No EPSS score is available, so the exploitation probability cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote via a crafted HTTP request to the exposed AJAX endpoint, and the required conditions are minimal: the site must host the affected plugin and the attacker need only be an unauthenticated visitor.
OpenCVE Enrichment