Executive brief
The Diet Calorie Calculator plugin for WordPress, which provides health and nutrition calculation tools for website visitors, contains a security flaw in its access control settings. This vulnerability allows unauthorized individuals to bypass intended security levels and potentially access information or perform actions that should be restricted to administrators. While the impact is considered moderate, it could lead to unauthorized data exposure or minor site manipulation.
Technical details
A missing authorization (CWE-862) vulnerability exists in the MWP Development Diet Calorie Calculator plugin for WordPress through version 1.1.1. The flaw stems from incorrectly configured access control security levels, which fail to properly validate user permissions before allowing access to certain functions or data. An unauthenticated remote attacker can exploit this by sending crafted network requests to the affected component. Depending on the specific implementation, this can lead to unauthorized data retrieval or the execution of restricted actions. As of the advisory date, no official patch has been released.
Affected products
- MWP Development Diet Calorie Calculator <= 1.1.1
Timeline
- 2026-01-22: other: Vulnerability reported by researcher
- 2026-02-21: disclosed: Initial disclosure by Patchstack
- 2026-04-08: advisory: CVE published