Impact
The vulnerability is a Missing Authorization flaw in the Salvador – AI Image Generator WordPress plugin. It permits users to access or manipulate the plugin’s image generation functionality without proper permission checks. The impact is that an unauthenticated or insufficiently privileged user could trigger AI image generation for arbitrary content, potentially enabling spam, content flooding, or indirect data exposure through generated media.
Affected Systems
The affected product is the Salvador – AI Image Generator plugin developed by awcode. All versions from the initial release up to and including 1.0.11 are vulnerable. Deployments of any of these versions on WordPress sites are at risk.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score of below 1% suggests a low probability of exploitation at the time of analysis. The issue is not listed in the CISA KEV catalog. The flaw arises from incorrectly configured access control security levels, which means that exploitation would likely be achieved through the plugin’s web interface by any user who can navigate to the generator endpoint. Attackers with basic web interaction capabilities could take advantage of the lack of authorization checks, although the vulnerability does not grant full system compromise.
OpenCVE Enrichment
EUVD