Impact
The Parallax Section block plugin contains a missing authorization flaw that permits attackers to invoke functionality that should be restricted by access control lists. This vulnerability could allow an unauthenticated or low‑privilege user to manipulate the plugin’s settings, view sensitive data, or potentially perform further actions within WordPress. The consequence is a breach of data confidentiality and integrity and could serve as a foothold for subsequent attacks if the plugin exposes additional privileged operations.
Affected Systems
All installations of the bPlugins Parallax Section block plugin with a version of 1.0.9 or earlier are affected. Versions prior to 1.0.9 are also vulnerable.
Risk and Exploitability
The CVSS base score of 7.1 indicates a high severity with medium to high exploitation potential. The EPSS score of less than 1% suggests the likelihood of exploitation is currently low, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector involves remote exploitation through the web interface, where an attacker can send crafted requests to the plugin’s endpoints to bypass authentication checks. No additional exploitation conditions are specified in the CVE data.
OpenCVE Enrichment