Impact
The vulnerability is a missing authorization flaw in the Christiaan Pieterse MaxiBlocks WordPress plugin. It allows an attacker to exploit incorrect access control security levels, potentially gaining unauthorized privileged actions such as modifying or deleting blocks. This flaw is categorized as CWE-862, indicating a lack of adequate authorization checks.
Affected Systems
Christiaan Pieterse MaxiBlocks plugin for WordPress. All installations of the plugin up to and including version 2.1.3 are vulnerable. No specific sub‑versions are listed beyond the upper bound of 2.1.3.
Risk and Exploitability
The CVSS score of 5.0 shows moderate severity, while the EPSS score of less than 1% indicates a very low probability of exploitation. The vulnerability is not reported in the CISA KEV catalog, so there are no known public exploits. Attackers would need to reach the WordPress site and use the plugin’s functions exposed to authenticated or unauthenticated users, depending on site configuration, to abuse the missing authorization controls.
OpenCVE Enrichment
EUVD