Impact
Missing authorization in the Flowbox plugin lets attackers exploit incorrectly set access control levels, enabling them to view or modify data and settings that should be protected. This can lead to content tampering, data leakage, or other unauthorized actions within the WordPress site.
Affected Systems
Vulnerable versions of the Flowbox WordPress plugin include all releases from the initial version through 1.1.6. Users running any of these versions are affected.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate impact, while the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, and no public exploit has been reported. Attackers can likely reach the flaw remotely through the WordPress web interface by accessing plugin configuration pages; the mechanism is inferred based on the nature of the access control issue.
OpenCVE Enrichment