Impact
The Xpro Theme Builder plugin up to version 1.2.9 contains a missing authorization flaw that allows attackers to use incorrectly configured access control levels. This vulnerability can let an attacker view or modify plugin settings and potentially tamper with site content or gain further foothold, as defined by CWE-862.
Affected Systems
The flaw affects the Xpro Theme Builder plugin for WordPress in all versions up to and including 1.2.9. No specific WordPress core version is listed as impacted.
Risk and Exploitability
With a CVSS score of 6.5 the vulnerability is rated medium severity, and the EPSS score of less than 1% indicates a low probability of exploitation. The vulnerability is not listed in CISA KEV. The CVE states that a missing authorization check allows attackers to use incorrectly configured access control levels. Therefore, if an attacker can reach the plugin’s administrative endpoints through the WordPress web interface, they may be able to view or alter plugin settings. The CVE does not detail whether an authenticated user is required or if unauthenticated users could exploit the flaw, so whether the attack requires authentication or not is a literal inference that may not hold in all deployments.
OpenCVE Enrichment
EUVD