Impact
The vulnerability is a missing authorization flaw that allows attackers to exploit incorrectly configured access control levels within the WordPress Editor Custom Color Palette plugin. This weakness enables an unauthorized user to manipulate the plugin’s custom color palette settings, potentially altering site appearance or embedding malicious data. The weakness is identified as CWE-862, indicating improper authorization controls.
Affected Systems
Rouergue Création’s Editor Custom Color Palette plugin, versions from its inception up through 3.5.6, is affected. Users running any of these versions are vulnerable until updated.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves an authenticated user who gains access to the plugin’s settings; the attacker would need sufficient privileges to reach the color palette feature, but can then submit unauthorized changes. No evidence of a publicly available exploit remains, however the risk is elevated for installations with many user accounts or where elevated privileges are widely granted.
OpenCVE Enrichment
EUVD