Impact
The Cool Author Box plugin contains a missing authorization check that permits users lacking proper permissions to change configuration settings, a flaw classified as CWE-862. This allows non-privileged users to manipulate plugin options or expose protected content, potentially affecting site appearance or data flow, but it does not grant direct code execution.
Affected Systems
The affected product is the Hossni Mubarak Cool Author Box plugin for WordPress. Versions from the earliest release up through 2.9.9 are vulnerable. All installations of the plugin within that version range are impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is below 1%, suggesting a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through the WordPress admin interface or crafted URLs that bypass proper access controls, requiring authenticated access without adequate privileges.
OpenCVE Enrichment
EUVD