CyberRota Analysis
AI-GeneratedThe GutenKit WordPress plugin prior to version 2.5.0 is vulnerable due to inadequate capability checks on certain REST API endpoints, enabling users with Contributor roles and higher to access sensitive mailing-list audience metadata from the site's marketing account. This could lead to unauthorized exposure of user data, posing a privacy risk. WordPress site administrators and those utilizing the GutenKit plugin should prioritize updating to the latest version to mitigate this vulnerability.
Original NVD Description
The GutenKit WordPress plugin before 2.5.0 does not have a sufficient capability check on some of its REST API endpoints, allowing users with the Contributor role and above to retrieve mailing-list audience metadata from the site's connected marketing account.