Impact
The vulnerability is a missing authorization flaw in the WordPress Testimonials Showcase plugin, allowing an attacker to manipulate testimonial content and potentially delete or alter entries. This flaw undermines data integrity and could be used to inject false or malicious testimonials, impacting the site’s credibility. The flaw is rooted in incorrect access control, classified under CWE‑862. The impact is limited to the testimonial data and does not provide remote code execution or broader system compromise.
Affected Systems
The vulnerable component is the cmoreira Testimonials Showcase plugin, with affected releases from its initial version through 1.9.16. Users running any of these versions are at risk unless they upgrade to a non‑vulnerable release.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity and the EPSS score of less than 1% suggests a low probability of exploitation. The bug is not listed in the CISA KEV catalog. Because the flaw originates from incorrect permission checks, the likely attack vector is via the WordPress administrative interface or through a user account that has been granted access to the plugin’s edit features. Observation of the description indicates that no special privileges are required beyond the standard access level used by legitimate administrators. However, exploitation would still require the attacker to act within the boundaries of the compromised credentials or to obtain a level of access that the plugin incorrectly trusts.
OpenCVE Enrichment
EUVD