Impact
The vulnerability is a missing authorization flaw that allows an attacker to bypass the access control checks in the bdthemes Ultimate Store Kit Elementor Addons plugin. This weakness is classified as CWE‑862: Missing Authorization. An attacker can alter or view plugin configurations that should be restricted, effectively elevating their privileges within the WordPress site.
Affected Systems
The affected product is the bdthemes Ultimate Store Kit Elementor Addons plugin for WordPress. All versions from the initial release through 2.3.0 are impacted. No other products or vendors are listed.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, while the EPSS score of less than 1% suggests that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a web‑based request to the plugin’s administrative endpoints; this is inferred from the missing authorization checks. An attacker would need at least the ability to reach the plugin’s settings interface, but the lack of proper access control could allow privilege escalation within the plugin’s scope.
OpenCVE Enrichment
EUVD