Impact
The vulnerability is a missing authorization flaw in the WordPress Behance Portfolio Manager plugin that allows incorrectly configured access control security levels. This defect permits unauthorized users to access protected resources that should be restricted, potentially exposing sensitive content or allowing further compromise. The weakness is classified as CWE‑862.
Affected Systems
The issue affects WordPress sites running the eleopard Behance Portfolio Manager plugin at any version up to and including 1.7.5. All earlier releases are also vulnerable; versions newer than 1.7.5 are not impacted.
Risk and Exploitability
The CVSS score of 4.3 places the vulnerability in the moderate range, while an EPSS score of less than 1% indicates a low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog, suggesting it is not widely known or actively exploited. The likely attack vector is inferred to involve the WordPress web interface – an attacker might need to leverage a user account with certain privileges or exploit administrative functions to reach the vulnerable plugin endpoints. No public exploit is currently available and mitigation is primarily achieved by applying vendor updates or implementing access controls.
OpenCVE Enrichment
EUVD