Impact
A missing authorization check in the picu Online Photo Proofing Gallery plugin allows an attacker to bypass the intended access controls and use functions that should be restricted, such as viewing or modifying photo proofs. The vulnerability is classified as Broken Access Control (CWE-862) and could permit unauthorized users to interact with sensitive gallery content.
Affected Systems
WordPress sites that have the picu plugin version 2.4.0 or earlier installed are impacted. The vendor/product is picu:picu, and all releases from the earliest available up to and including 2.4.0 contain the flaw.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score of less than 1% suggests exploitation is unlikely at present, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, an attacker who can reach the plugin’s administrative endpoints may exploit the broken access control to gain unauthorized access, depending on the site’s user configuration. Remote exploitation is inferred from the need to invoke protected URLs directly.
OpenCVE Enrichment
EUVD