Impact
The vulnerability is a Missing Authorization flaw in the POSIMYTH Nexter Blocks plugin, also known as the-plus-addons-for-block-editor. It stems from incorrectly configured access control security levels. When triggered, it allows a user to access or modify data and privileged functions that they should not be able to reach. The weakness is classified as CWE‑862.
Affected Systems
The affected product is the POSIMYTH Nexter Blocks plugin, named the-plus-addons-for-block-editor. All releases from the earliest version through version 4.5.4 are vulnerable, so any WordPress site running the plugin at these or older versions is at risk.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity overall. The EPSS score is below 1 %, suggesting that the likelihood of public exploitation is very low at present. The vulnerability is not included in CISA’s KEV catalog. Based on the description, it is inferred that an attacker would need to have some level of authenticated WordPress access, such as an editor or administrator role, but the missing authorization check allows them to perform actions beyond their intended permissions. Mitigation is straightforward by applying a patch or removing the plugin from the site.
OpenCVE Enrichment
EUVD