Impact
The vulnerability is a missing authorization flaw that allows an attacker to abuse incorrectly configured access control settings. This flaw permits users to perform functions beyond their intended privileges, potentially altering or adding content. The impact is a compromise of content integrity and the ability to create or modify pieces on the site, which can lead to defacement or insertion of malicious code.
Affected Systems
The weakness affects the Stackable block editor plugin developed by Benjamin Intal, specifically all releases from the earliest available version up to and including 3.18.1. Sites running any of these plugin versions on WordPress are at risk and should consider upgrading.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate threat level, and an EPSS score of less than 1% suggests exploitation is unlikely at present. At present the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a legitimate user with insufficient privileges who can exploit the mis-configured access control settings, though the exact vector is not detailed in the description
OpenCVE Enrichment
EUVD