Impact
Missing authorization in the WordPress WP News Sliders plugin allows exploitation of incorrectly configured access control levels. An attacker who can reach the plugin’s endpoints could gain unauthorized access to the plugin’s configuration settings, potentially enabling tampering with or misrepresenting content presented on the site.
Affected Systems
The vulnerability affects the codeaffairs WP News Sliders plugin versions from an unspecified initial release up to and including version 1.0. Any WordPress site that has installed the WP News Sliders plugin with a version <= 1.0 is impacted.
Risk and Exploitability
The CVSS score of 4.3 suggests moderate impact, while the EPSS score of less than 1% indicates a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation is inferred to occur via web-based requests to the plugin’s administrative endpoints, but the exact attack vector is not explicitly documented in the provided information. The lack of a formal solution in the CNA data suggests that upgrading the plugin or applying a temporary access control workaround is the recommended approach.
OpenCVE Enrichment
EUVD