Impact
The vulnerability is a missing authorization flaw in the CreedAlly Bulk Featured Image plugin that allows attackers to bypass normal WordPress access controls and change or upload featured images on posts or pages. This flaw can be used to alter page content, potentially defacing a site by replacing images or embedding malicious media.
Affected Systems
Affected systems are all WordPress installations that use the CreedAlly Bulk Featured Image plugin version 1.2.4 or earlier, as the issue applies from the component’s initial release up to and including 1.2.4.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate impact, and the EPSS score of less than 1% suggests that exploitation is currently considered unlikely. The vulnerability is not listed in CISA’s KEV catalog, pointing to low visibility in known exploit chains. Attackers would likely target users who have been granted permissions to use the plugin; based on the description, it is inferred that the usual vector is a compromised WordPress account with sufficient privileges.
OpenCVE Enrichment
EUVD