Impact
The Sticky Header On Scroll plugin for WordPress contains a missing authorization flaw (CWE‑862) that allows attackers to exploit incorrectly configured access control levels. Attackers may be able to change plugin settings through administrative interfaces that lack proper permission checks, potentially enabling further malicious activity on the affected site.
Affected Systems
WordPress sites using the Hardik Sticky Header On Scroll plugin version 1.0 or earlier. The lower bound of affected versions is not specified.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, while the EPSS score of <1% suggests a low likelihood of exploitation in the wild. This vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the attack vector involves accessing the plugin’s administrative endpoints that lack proper authorization checks, but the specific authentication requirements are not detailed in the CVE record.
OpenCVE Enrichment
EUVD