Impact
The KBoard plugin before version 6.7 fails to verify ownership or context when deleting board media, allowing unauthenticated attackers to delete uploaded media files and their database records by iterating identifiers. This flaw causes loss of data integrity and can result in site downtime if critical content is removed. The weakness is an Insecure Direct Object Reference (IDOR) identified as CWE‑639.
Affected Systems
WordPress sites that use the KBoard plugin at or below version 6.6 are affected. Any installation exposing the media deletion endpoint to the public without authentication is at risk, regardless of site size or user base.
Risk and Exploitability
The CVSS score of 5.3 suggests a medium severity vulnerability, while the EPSS score of less than 1 % indicates a low current exploitation probability. The vulnerability is not listed in CISA KEV. Attackers can exploit the flaw by sending authenticated‑neutral HTTP requests to the deletion endpoint, iterating through media identifiers, and permanently deleting data. The risk is therefore moderate, with a low chance of exploitation but significant potential impact if an attack occurs.
OpenCVE Enrichment