Impact
The Advanced Dewplayer plugin contains a missing authorization flaw that permits exploitation of incorrectly configured access control levels. An attacker who can reach the plugin’s exposed functions may gain unauthorized access to the plugin’s configuration or content management features, potentially allowing modification or reading of data beyond intended privileges.
Affected Systems
WordPress sites running the WesternDeal Advanced Dewplayer plugin version 1.6 or earlier are affected. The vulnerability manifests in all installations of the plugin dating from its initial release up to and including version 1.6.
Risk and Exploitability
With a CVSS score of 5.3 the issue is considered moderate severity. The EPSS score of less than 1% indicates a low probability of exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The likely attack path involves a remote attacker accessing plugin endpoints that lack proper authorization checks; successful exploitation would provide unauthorized administrative access
OpenCVE Enrichment
EUVD