Description
Missing Authorization vulnerability in Ella Van Durpe Slides & Presentations slide allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Slides & Presentations: from n/a through <= 0.0.39.
Published: 2025-01-07
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a missing authorization flaw that allows users to bypass access control settings while managing slides in the Slides & Presentations plugin. An attacker who can reach the plugin’s administrative interface or has any authenticated role can add, edit, or delete slides without the proper permissions, potentially hijacking presentation content and exposing sensitive information. The weakness is identified as CWE‑862. The impact is limited to the scope of the plugin’s operations but can be significant if the slides contain confidential data.

Affected Systems

WordPress sites that install the Ella Van Durpe Slides & Presentations plugin version 0.0.39 or earlier. No specific operating system or WordPress core version is tied to the issue; the vulnerability applies to all environments where the plugin is deployed.

Risk and Exploitability

The CVSS score of 5.4 indicates a medium severity with limited impact. The EPSS score is below 1%, suggesting that exploitation is currently unlikely to be widespread. The vulnerability is not listed in CISA’s KEV catalog, so there are no known large‑scale exploits. The attack vector is inferred to be from any user who can authenticate to the WordPress site and interact with the plugin, as there is no explicit remote code execution or denial of service described. If the site’s role permissions grant broader access than intended, the flaw can be leveraged to compromise presentation data.

Generated by OpenCVE AI on May 1, 2026 at 22:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Slides & Presentations plugin to the first release above 0.0.39, which removes the broken access control logic.
  • If upgrading immediately is not possible, restrict plugin usage to the Administrator role and revoke slide management capabilities from lower‑privileged roles.
  • Disable the plugin for unauthenticated visitors and ensure that any authenticated user only has the exact permissions required for their role.

Generated by OpenCVE AI on May 1, 2026 at 22:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-2812 Missing Authorization vulnerability in Ella van Durpe Slides & Presentations allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Slides & Presentations: from n/a through 0.0.39.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Ella van Durpe Slides & Presentations allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Slides & Presentations: from n/a through 0.0.39. Missing Authorization vulnerability in Ella Van Durpe Slides & Presentations slide allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Slides & Presentations: from n/a through <= 0.0.39.
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


Tue, 07 Jan 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 07 Jan 2025 15:30:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Ella van Durpe Slides & Presentations allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Slides & Presentations: from n/a through 0.0.39.
Title WordPress Slides & Presentations Plugin <= 0.0.39 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:00.962Z

Reserved: 2025-01-07T10:22:58.148Z

Link: CVE-2025-22534

cve-icon Vulnrichment

Updated: 2025-01-07T16:40:12.807Z

cve-icon NVD

Status : Deferred

Published: 2025-01-07T16:15:49.130

Modified: 2026-06-17T08:48:04.210

Link: CVE-2025-22534

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T22:30:16Z

Weaknesses