Impact
The vulnerability is a Missing Authorization flaw that lets an attacker use capabilities not properly constrained by ACLs in the solwin Blog Designer PRO plugin. It could allow unauthorized creation, modification, or deletion of blog designs, compromising site content integrity and confidentiality. The weakness is classified as CWE-862, indicating an improper restriction on authenticated users.
Affected Systems
The affected product is the WordPress plugin solwin Blog Designer PRO, versions up to and including 3.4.8, which is distributed via the WordPress plugin repository. WordPress sites that have installed this plugin without applying the latest update are at risk.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is less than 1%, pointing to a low likelihood of exploitation today, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need authenticated access to the WordPress installation, but the policy check is bypassed, so any user who can install or configure the plugin could potentially gain unauthorized privileges. The likely attack vector is internal users or compromised accounts with plugin management rights.
OpenCVE Enrichment