Impact
A broken access control flaw in the Classic Widgets with Block-based Widgets plugin allows an attacker to call functions that should be restricted by the plugin’s access control lists. The vulnerability, identified as CWE‑862, could enable a malicious user to perform administrative actions or view data that should be limited to authorized roles, thereby compromising the integrity and confidentiality of the WordPress site.
Affected Systems
The vulnerability affects the WordPress plugin Classic Widgets with Block-based Widgets delivered by Sumit Singh in all releases up to and including version 1.0.1. Sites still using any of these versions are vulnerable, regardless of the broader WordPress installation version.
Risk and Exploitability
Based on the description, the plugin's HTTP endpoints are exposed to all users, enabling unauthorized invocation of privileged functions. The EPSS score of <1% suggests a low probability of public exploitation, and the issue is not listed in CISA KEV. The CVSS 5.3 score indicates moderate severity, meaning a determined attacker could compromise the site's confidentiality or integrity by exploiting this oversight. Accordingly, the overall risk should be treated as medium but warrants prompt action.
OpenCVE Enrichment
EUVD