Impact
The vulnerability is a missing authorization flaw that allows the exploitation of incorrectly configured access control levels in the eDS Responsive Menu plugin. An attacker could potentially access restricted plugin functionality or data without proper credentials, which maps to CWE-862. The vulnerability is limited to plugin operations and does not directly compromise core WordPress or other site components unless those plugin features provide privileged actions.
Affected Systems
The affected product is the aThemeArt Translations eDS Responsive Menu WordPress plugin, versions from the earliest supported release through 1.2. Users running the plugin at version 1.2 or earlier are vulnerable; newer releases are not affected.
Risk and Exploitability
The CVSS score of 4.3 classifies the issue as a moderate risk. The EPSS score of less than 1% indicates a very low probability of exploitation in the wild at the time of assessment, and the vulnerability is not listed in the CISA KEV catalog. While the attack vector is not explicitly detailed, the flaw likely requires an attacker to send crafted requests or meddle with configuration settings within a WordPress site, implying that the risk is confined to compromised or weakly protected installations.
OpenCVE Enrichment
EUVD