Impact
A missing authorization flaw in the bPlugins Animated Text Block WordPress plugin permits unauthorized users to access the plugin’s configuration and content. This could allow an attacker to alter displayed text or modify the way content is rendered, compromising the integrity of the website.
Affected Systems
WordPress installations that use the bPlugins Animated Text Block plugin version 1.0.7 or earlier are affected. No other vendors or products are impacted by this vulnerability.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalogue. The likely attack vector is exploitation of the WordPress admin interface, as the vulnerability involves access to plugin configuration pages. Based on the description, it is inferred that any user who can reach the plugin’s configuration endpoints could bypass intended access controls.
OpenCVE Enrichment
EUVD