Impact
The vulnerability is a missing authorization flaw in the News Kit Elementor Addons plugin. This flaw allows an attacker to bypass the configured access control for protected actions within the plugin. By exploiting this weakness, a threat actor can perform unauthorized actions that may include creating, editing, or deleting content that should otherwise be restricted, potentially compromising the integrity and confidentiality of site data.
Affected Systems
The affected product is the blazethemes News Kit Elementor Addons plugin for WordPress. All installations of the plugin with versions up to and including 1.3.4 are vulnerable. No fixed version is noted in the description; versions prior to 1.3.5 are affected.
Risk and Exploitability
The CVSS score of 5.4 reflects moderate severity. The EPSS score is less than 1%, indicating a very low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a web‑based request directed to the plugin’s administrative endpoints, potentially requiring authenticated access to perform privileged actions. Due to the absence of a listed official fix, administrators should urgently upgrade the plugin or remove it.
OpenCVE Enrichment
EUVD