Impact
A missing authorization flaw in the GPP Slideshow WordPress plugin lets attackers bypass normal access controls. The flaw is due to incorrectly configured security levels, enabling unauthorized users to perform actions that should be restricted. This can lead to a range of consequences, including unauthorized configuration changes, visibility of protected content, or other elevated privileges within sites running the vulnerable plugin.
Affected Systems
The vulnerability touches WordPress sites that have the GPP Slideshow plugin installed at version 1.3.5 or earlier. The affected component is the plugin itself, which provides slideshow functionality in WordPress themes and pages.
Risk and Exploitability
The CVSS score of 4.3 signals a moderate impact with limited damage potential. An EPSS score below 1% suggests that exploitation of this weakness is unlikely at present, and it is not listed in the CISA KEV catalog. Nonetheless, the vulnerability requires a path through the plugin’s authentication checks, meaning stakeholders should validate that the plugin’s access controls are properly enforced before firewall or network perimeter measures can prevent exploitation.
OpenCVE Enrichment
EUVD