Impact
The flaw is a missing authorization check in the WordPress plugin that allows an attacker to use operations that should be restricted to privileged users, potentially granting arbitrary access to sensitive functions or data within the plugin. This Weakness is identified as CWE‑862, highlighting that the application fails to enforce appropriate access controls.
Affected Systems
The plugin affected is WPZOOM’s Recipe Card Blocks for Gutenberg & Elementor. Versions up to and including 3.4.3 are vulnerable. No specific vendor‑certified version numbers beyond the upper bound of 3.4.3 are listed.
Risk and Exploitability
The vulnerability has a CVSS score of 4.3, indicating moderate impact. The EPSS score is below 1%, suggesting low current exploitation likelihood, and it is not listed in the CISA KEV catalog. The attack vector is inferred to be through the web interface of a WordPress site hosting the plugin, where an authenticated or unauthenticated visitor may exploit the broken access control to elevate privileges or gain unauthorized access.
OpenCVE Enrichment
EUVD