Impact
The vulnerability is a missing authorization check in the Melodic Media Slide Banners WordPress plugin, which allows an attacker to bypass the intended access control. An actor could potentially execute privileged actions within the plugin, such as creating, editing, or deleting slide banners, without proper authentication or authorization. The CVSS score of 4.3 indicates that the impact is moderate but not life‑threatening. The weakness is classified as CWE‑862, a classic missing authorization flaw.
Affected Systems
The affected product is the Slide Banners plugin by Melodic Media used within WordPress installations. All installations of version 1.3 or earlier are impacted, while newer releases are not mentioned in the CVE.
Risk and Exploitability
The EPSS score is less than 1%, suggesting a low probability of being actively exploited in the wild. Because the vulnerability is not listed in the CISA KEV catalog, there is no known active exploitation. The likely attack vector is remote, via normal WordPress request paths to the plugin, provided the attacker can access the site. Thus, the risk remains moderate but could be elevated if the plugin is widely deployed without other controls.
OpenCVE Enrichment
EUVD