Impact
A flaw in the WordPress Netgsm plugin allows a malicious actor to bypass authentication checks without any credentials. This bypass can potentially enable the attacker to perform privileged actions that the plugin normally restricts, compromising the confidentiality and integrity of the site content and any data processed by the plugin.
Affected Systems
The vulnerability affects all users of Netgsm version 2.10.0 and earlier running on WordPress. It is not limited to specific operating systems or server configurations, and any WordPress site that has the Netgsm plugin installed in a vulnerable version is impacted.
Risk and Exploitability
The CVSS score of 5.3 categorises the issue as medium severity, and no EPSS score is available to indicate current exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through the plugin’s exposed functionality; an unauthenticated user can trigger the bypass via a crafted request to the plugin’s endpoint. Exploitation requires only the presence of a vulnerable plugin instance and does not depend on specialised privileges or equipment.
OpenCVE Enrichment