Impact
This vulnerability is a missing authorization flaw that allows an attacker to bypass access control on the Simple Photo Feed plugin. As a result, an individual without proper privileges could read photo feed data that should be protected. The weakness is a classic broken access control (CWE-862).
Affected Systems
The issue affects the WordPress Simple Photo Feed plugin developed by George Pattichis, versions up to and including 1.4.0.
Risk and Exploitability
The CVSS score of 5.4 classifies the vulnerability as moderate, and the EPSS score of less than 1% indicates a low likelihood of exploitation. Because it is not listed in the CISA KEV catalog, there is no documented active exploitation. The likely attack vector is through the web interface or API endpoints of the plugin, enabling a remote attacker with HTTP access to interact with protected data.
OpenCVE Enrichment
EUVD