Description
Missing Authorization vulnerability in averta Master Slider master-slider.This issue affects Master Slider: from n/a through <= 3.11.0.
Published: 2025-05-19
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing authorization flaw in Master Slider allows an attacker who can reach the WordPress administration interface to manipulate slider content, add slides, or delete existing ones without proper permission checks. The vulnerability, categorized as CWE‑862, could lead to integrity and availability disruptions on the site, as an attacker may alter or remove essential visual elements. The CVSS score of 4.3 reflects a low severity rating, indicating that the defect does not enable arbitrary code execution or confidential data disclosure by itself.

Affected Systems

The flaw impacts the Master Slider plugin developed by averta, affecting all installations from the earliest release through version 3.11.0. Any WordPress site that has never upgraded beyond 3.11.0 is potentially vulnerable, including the reported 3.10.7 build. The affected versions include those in the identified range, and the vulnerability applies to the entire plugin code base under these releases.

Risk and Exploitability

The EPSS score is reported as <1%, indicating a very low probability of exploitation observed in the wild. The CVSS rating of 4.3 and absence from the CISA KEV catalog suggest that the overall risk is moderate but not critical. The likely attack vector is an authenticated user who has access to the WordPress back‑end but lacks the proper authorization to manage sliders; this inference is drawn from the description’s mention of missing authorization and does not state an explicit external exploitation path.

Generated by OpenCVE AI on April 30, 2026 at 19:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Master Slider to a version newer than 3.11.0, applying any vendor‑supplied patches that address the authorization flaw
  • Immediately review and tighten WordPress user roles, ensuring that only trusted administrators have access to slider creation, editing, and deletion
  • Regularly audit plugin updates and user permissions, and maintain recent backups to allow rapid restoration in case of unauthorized changes

Generated by OpenCVE AI on April 30, 2026 at 19:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-27952 Missing Authorization vulnerability in Averta Master Slider.This issue affects Master Slider: from n/a through 3.10.8.
History

Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Averta Master Slider.This issue affects Master Slider: from n/a through 3.10.8. Missing Authorization vulnerability in averta Master Slider master-slider.This issue affects Master Slider: from n/a through <= 3.11.0.
Title WordPress Master Slider plugin <= 3.10.8 - Broken Access Control vulnerability WordPress Master Slider plugin <= 3.11.0 - Broken Access Control vulnerability
References

Tue, 27 May 2025 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Averta
Averta master Slider
CPEs cpe:2.3:a:averta:master_slider:*:*:*:*:*:wordpress:*:*
Vendors & Products Averta
Averta master Slider

Tue, 20 May 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 19 May 2025 17:30:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Averta Master Slider.This issue affects Master Slider: from n/a through 3.10.8.
Title WordPress Master Slider plugin <= 3.10.8 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Averta Master Slider
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:30.622Z

Reserved: 2025-04-16T06:22:58.198Z

Link: CVE-2025-39412

cve-icon Vulnrichment

Updated: 2025-05-20T13:12:09.840Z

cve-icon NVD

Status : Modified

Published: 2025-05-19T18:15:29.187

Modified: 2026-04-23T15:29:30.247

Link: CVE-2025-39412

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T19:45:26Z

Weaknesses