Impact
The vulnerability is a missing authorization flaw that allows an attacker to circumvent the plugin’s access control checks, potentially permitting unauthorized access to, alteration of, or deletion of plugin configuration data and content managed by Specia Companion. The weakness is identified as CWE-862.
Affected Systems
The issue affects the Specia Theme Specia Companion WordPress plugin for all versions up to and including 6.3. The affected product is the Specia Companion plugin distributed through the Specia Theme family.
Risk and Exploitability
The CVSS base score of 6.5 indicates moderate severity. The EPSS score of less than 1% shows a low likelihood of widespread exploitation, and the vulnerability is not currently listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker would need to interact with the plugin’s administrative interface to exploit the flaw. The exact prerequisites for that interaction, such as authentication level or user permissions, are not detailed in the CVE record.
OpenCVE Enrichment
EUVD