Impact
The SKT Page Builder plugin contains a missing authorization flaw that permits users to perform actions that should be restricted to privileged accounts. This broken access control can enable an attacker to modify or delete content, potentially altering site appearance or functionality. The weakness is a classic missing permission check, as identified by CWE‑862.
Affected Systems
This vulnerability affects the WordPress SKT Page Builder plugin produced by sonalsinha21. Versions from the earliest release through 4.9 are vulnerable.
Risk and Exploitability
The vulnerability has a CVSS score of 4.3, placing it in the moderate range. Its EPSS score is below 1 %, implying a low probability that it will be actively exploited at this time. The vulnerability is not listed in CISA KEV. Based on the nature of WordPress plugins, the likely vector is remote web‑based exploitation via standard HTTP requests to the plugin’s administrative endpoints, assuming attacker has network access to the site and the plugin is reachable.
OpenCVE Enrichment