Impact
The vulnerability is a missing authorization issue in the Image Hover Effects – Elementor Addon plugin for WordPress, allowing attackers to bypass configured access control settings. It enables unauthorized users to perform actions that are intended to be protected by the plugin’s access control logic, potentially leading to further exploitation. The weakness is identified as CWE‑862.
Affected Systems
This flaw affects the Image Hover Effects – Elementor Addon by Blocksera for WordPress. All versions from the earliest release through 1.4.4 are vulnerable. Systems running WordPress sites that have this plugin installed and have not upgraded past version 1.4.4 are impacted.
Risk and Exploitability
Based on the description, the probable attack vector involves local or remote access to WordPress administrative functions, exploiting the plugin’s incorrectly configured access control. The CVSS score of 5.3 indicates medium severity, but the EPSS score of less than 1% suggests exploitation is unlikely at this time. The vulnerability is not included in the CISA KEV catalog, so there is no evidence of widespread exploitation.
OpenCVE Enrichment
EUVD