Impact
The Aruba Migration Tool WordPress plugin, up through version 1.0.4, contains a broken access control flaw that allows an authenticated user with subscriber role or minimal privileges to perform migration operations originally restricted to higher‑privilege accounts. This flaw permits the user to alter or delete migration data, potentially compromising data integrity and confidentiality by exposing or modifying site content during migration procedures. The weakness is identified as CWE‑862, a classic access control breach. Based on the description, it is inferred that an authenticated subscriber can exploit this flaw.
Affected Systems
Known affected product: Aruba.it Aruba Migration Tool plugin for WordPress, versions up to and including 1.0.4. No specific EOL or patch notes are listed beyond the indication that version 1.0.5 includes the fix.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium to high severity. No EPSS score is available, so the exploitation likelihood cannot be quantified from the data provided; the KEV status is not listed. The likely attack vector is through a WordPress site where the plugin is installed; the flaw can be leveraged by an authenticated user with subscriber role or minimal privileges to send crafted requests to the migration endpoint, bypassing the intended restriction, and carrying out unauthorized migration actions.
OpenCVE Enrichment