Impact
The vulnerability is a classic missing authorization flaw that allows attackers to bypass normal access controls within WordPress Spice Blocks. By exploiting incorrectly configured security levels, an attacker could gain unauthorised access to administrative functions and potentially tamper with or view content that should be protected. The weakness is classified as CWE‑862 and could lead to confidential data leakage or site manipulation.
Affected Systems
Any WordPress installation that uses Spice Themes Spice Blocks plugin version 2.0.7.7 or earlier is affected, regardless of the overall WordPress version. No specific WordPress core or OS version requirement is noted.
Risk and Exploitability
The CVSS score of 7.5 designates the flaw as high severity, while the EPSS score of less than 1% indicates a low probability of exploitation at present. The vulnerability is not present in the CISA KEV catalog. The attack is likely application‑level, requiring the attacker to interact with plugin‑specific URLs to elevate privileges; no network‑level attacker capability is required beyond typical web traffic. If successful, the attacker can execute actions normally guarded by authentication.
OpenCVE Enrichment
EUVD