Impact
Unauthenticated Broken Access Control in AppMySite plugin versions 3.15.4 and earlier allows an attacker to access or manipulate data that should be restricted to authenticated users. The flaw could lead to unauthorized modification or deletion of content, potential disclosure of sensitive information, and overall compromise of integrity within the affected WordPress site.
Affected Systems
WordPress sites that use the AppMySite plugin version 3.15.4 or earlier are affected. The plugin is a third‑party extension for WordPress installations, and any site running these versions without the update is vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity. Exploitation is possible over the internet with no authentication, implying a remote attack vector. Because no EPSS score is available and the vulnerability is not listed in the KEV catalog, the exact likelihood of real‑world exploitation is uncertain, but the potential damage warrants prompt remediation.
OpenCVE Enrichment