Impact
The vulnerability is a missing authorization flaw in GB Gallery Slideshow that permits unauthorized users to interact with plugin configuration and potentially manipulate gallery content. The flaw stems from incorrect access control enforcement, classified as CWE-862. Users who are not properly authenticated or lack the necessary permissions can access restricted settings or data within the plugin.
Affected Systems
The affected product is the GB Gallery Slideshow plugin for WordPress, specifically all releases from the initial release up to and including version 1.3. No further version granularities are listed, so any installation of the plugin that has not been upgraded beyond 1.3 is vulnerable.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation. This vulnerability is not currently listed in the CISA KEV catalog. Although the official description does not specify the attack vector, the nature of a broken access control in a WordPress plugin implies that the exploit could be performed through the web interface by sending crafted requests to privileged URLs. No special conditions are required beyond the ability to reach these URLs, making the flaw potentially accessible to unauthenticated or partially privileged users.
OpenCVE Enrichment
EUVD