Impact
The CVE describes an Insecure Direct Object Reference vulnerability in the WordPress SiteSkite plugin. The flaw allows an attacker with sufficient access to bypass authentication checks and retrieve or modify resources that should be restricted to authorized users, leading to potential disclosure or alteration of sensitive content.
Affected Systems
All installations of the SiteSkite plugin up to and including version 2.1.7 on WordPress sites are impacted. Users running the affected plugin version are potentially exposed.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is web‑based, involving manipulation of URL parameters or API calls that reference protected objects. Exploitation probably requires authenticated access and input manipulation, enabling the attacker to access data unintended for them.
OpenCVE Enrichment