Impact
The vulnerability is a missing authorization flaw that allows adversaries to perform actions they should not be able to do within the Templazee plugin. The flaw arises from incorrectly configured access control security levels, enabling exploitation and potentially granting access to sensitive data or administrative capabilities. This issue is officially identified as a broken access control vulnerability.
Affected Systems
All installations of the WordPress Templazee plugin, versions from the earliest release through version 1.0.2, are vulnerable. The affected product is the Templazee plugin for WordPress, provided by the templazee vendor.
Risk and Exploitability
The CVSS score of 5.4 indicates medium severity, and the EPSS score of less than 1% suggests a low but non-zero probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Attackers would need the plugin installed and exposed on a WordPress site; once available, the missing authorization checks could be used to elevate permissions or access restricted resources. Given the moderate score and low exploitation likelihood, the risk is present but manageable with timely remediation.
OpenCVE Enrichment