Impact
The nK Lazy Blocks plugin for WordPress contains a missing authorization issue that allows an attacker to exploit incorrectly configured access control security levels. This vulnerability permits unauthorized users to potentially perform operations they should not be able to, compromising the integrity of site content and potentially exposing sensitive information.
Affected Systems
The vulnerability affects the Lazy Blocks plugin in all versions from the earliest available release through 4.1.0. Administrators and developers should verify whether their installations use the legacy plugin and plan for an upgrade.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate risk, and the EPSS score of less than 1% suggests a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a web‑based request to the plugin’s administrative interface; it is inferred that an attacker may be able to elevate privileges or perform restricted actions depending on configuration, but the exact scope of exploitation is not disclosed in the provided data.
OpenCVE Enrichment
EUVD