Impact
The vulnerability arises from a missing authorization check in the ACME Divi Modules plugin, allowing attackers to exploit incorrectly configured access control policies. This flaw can enable malicious actors to gain unauthorized access to sensitive administrative functions or configuration data within a WordPress installation, potentially leading to the exposure or modification of website content and settings.
Affected Systems
The affected vendor is acmemediakits, whose ACME Divi Modules WordPress plugin is vulnerable in all releases through and including version 1.3.5.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate impact, and the EPSS score of < 1% shows a very low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been observed in the wild. The likely attack surface is a remote web interface, where an authenticated user with any role could exploit the missing authorization to access or modify protected resources, although the full breadth of impact depends on the site's configuration.
OpenCVE Enrichment
EUVD