Impact
This vulnerability is a missing authorization flaw that permits users to access functions not properly constrained by access control lists. The weakness allows any actor to exercise actions normally restricted to privileged users, potentially exposing or modifying data included in the testimonial content or administration controls.
Affected Systems
WordPress installations using the Strong Testimonials plugin version 3.2.3 or earlier, distributed by WP Chill. All releases prior to 3.2.4 are vulnerable.
Risk and Exploitability
The CVSS v3.1 score of 5.3 indicates a moderate severity. The EPSS score of less than 1% shows the likelihood of exploitation is low; however, because the flaw is remotely exploitable through the web interface and not listed in the CISA KEV catalog, administrators should still prioritize remediation.
OpenCVE Enrichment
EUVD