Impact
The vulnerability is a missing authorization flaw in the Blog Designer plugin. An attacker who can send requests to the plugin front‑end could perform administrative actions or view sensitive content that should be protected. This flaw is classified as CWE‑862, indicating improper validation of privileges. The impact is restricted to data confidentiality and integrity, as the attacker can gain access to data that should be limited to privileged users.
Affected Systems
The affected product is the Blog Designer plugin from SolwinInfotech. Versions from the initial release up through 3.1.8 are impacted; any installation running 3.1.8 or earlier is vulnerable.
Risk and Exploitability
The CVSS score of 5.4 reflects moderate severity. The EPSS score of less than 1% indicates a very low likelihood of exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through web requests to the plugin’s administrative endpoints; an attacker would need network or web access to the WordPress site. No additional system prerequisites are noted in the description.
OpenCVE Enrichment
EUVD