Impact
The WP Sliding Login/Dashboard Panel plugin for WordPress contains a missing or incorrect nonce validation in the wp_sliding_panel_user_options() function. This flaw allows an unauthenticated attacker to send a forged request that updates plugin settings when a site administrator mistakenly clicks a crafted link. When exploited, the attacker can modify the plugin’s configuration without authentication, potentially changing any settings exposed by the plugin.
Affected Systems
Any WordPress installation that uses WP Sliding Login/Dashboard Panel version 2.1.1 or older is affected. The vulnerability exists in every instance of the plugin, regardless of other WordPress configuration.
Risk and Exploitability
The CVSS score of 4.3 classifies the vulnerability as moderate, while an EPSS score of < 1 % indicates a low likelihood of exploitation. The attack requires an adversary to convince an administrator to visit a malicious URL; no privileged or network compromise is needed. Because the attacker can alter settings by tricking a legitimate user, the risk remains even though the vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment
EUVD