Impact
The flaw is a missing authorization issue that allows a user to change configuration options within the ST Gallery WP WordPress plugin without the necessary permissions. As a result, an attacker could potentially alter the plugin’s behavior or enable additional features that may weaken site security. This weakness is classified as CWE‑862, indicating improper authorization.
Affected Systems
All installations of the beautifultemplates ST Gallery WP plugin for WordPress that are version 1.0.8 or older are affected.
Risk and Exploitability
The CVSS score of 5.4 places the vulnerability in the moderate severity range. The EPSS score of less than 1% implies a very low likelihood of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through the plugin’s settings interface, which an attacker may reach by possessing any user role that can access that page or, in the worst case, an unauthenticated attacker if the access controls are completely absent. Based on the description, it is inferred that the exploit does not require elevated privileges or additional prerequisites beyond access to the plugin’s settings page.
OpenCVE Enrichment
EUVD