Impact
The vulnerability is a missing authorization flaw that enables an attacker to perform unauthorized actions within the WordPress Simple Icons plugin. This incorrect configuration of access control security levels is classified as CWE-862 and can allow non‑privileged users to manipulate plugin settings or other restricted features. The impact is the potential escalation of privileges within the plugin’s functionality, which could be leveraged to affect the overall WordPress site in a limited manner.
Affected Systems
The issue affects the Travis:Simple Icons WordPress plugin from the earliest releases through version 2.8.4. Systems running WordPress with any of these plugin versions are at risk, regardless of the specific WordPress core version.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, and the EPSS score of under 1% shows a very low probability of exploitation at present. Because the vulnerability is not listed in the CISA KEV catalog, it is not known to be actively exploited by threat actors. The likely attack vector is via the web interface of the WordPress site, where an unauthenticated or low‑privileged user can send crafted requests to interact with the plugin. No special access or credentials are required beyond the permissions set by the plugin’s default configuration.
OpenCVE Enrichment
EUVD