Impact
The Thim Core plugin up to version 2.3.3 contains a missing authorization flaw that allows a user to override intended access controls. This flaw is identified as a lack of proper authorization checks, enabling exploitation of incorrectly configured security levels to perform actions beyond the intended permissions.
Affected Systems
WordPress sites that use the ThimPress Thim Core plugin, versions up to and including 2.3.3. The issue spans all installations of the plugin that have not been upgraded beyond this version.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate risk. EPSS is not available, and the vulnerability is not listed in the KEV catalog. The description does not disclose a specific attack vector or exploitation conditions; thus, the likelihood or typical exploitation scenarios cannot be determined from the available data.
OpenCVE Enrichment