Impact
The vulnerability is a missing authorization flaw in the slui Media Hygiene plugin that allows attackers to exploit improperly configured access control levels. This broken access control can enable unauthorized users to view, manage, or alter media items within a WordPress site. The flaw results in a moderate CVSS score of 5.4, indicating potential for privacy or integrity compromise. No direct evidence of remote code execution is provided in the description.
Affected Systems
The affected product is the Media Hygiene plugin for WordPress, developed by slui. All releases up to and including version 4.0.0 are impacted. No later versions are affected according to the data available.
Risk and Exploitability
The CVSS score of 5.4 reflects moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to exploit the plugin’s access control misconfiguration, which likely requires at least a minimally privileged WordPress user role or an authenticated session. The lack of publicly disclosed exploits means the risk is primarily theoretical, but enterprises should not ignore the possibility of internal users abusing the flaw.
OpenCVE Enrichment
EUVD