Impact
The Vulnerability Prevent files / folders access plugin in WordPress versions up to 2.6.7 contains a broken access control flaw identified as CWE‑862. A user who can authenticate with a subscriber‑level account is able to bypass the intended restrictions and retrieve private files or directories via the plugin’s interface, potentially exposing sensitive data.
Affected Systems
WordPress sites that have installed miniOrange’s Prevent files / folders access plugin at versions 2.6.7 or earlier. The issue is specific to the plugin, not the core WordPress installation, but any site using a vulnerable plugin is at risk.
Risk and Exploitability
The CVSS score for this vulnerability is 4.3, indicating a moderate potential impact. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, a subscriber or other authenticated user can exploit the flaw to access protected files; the attack vector is likely within the application, requiring an authenticated session but not privileged system access.
OpenCVE Enrichment