Impact
The vulnerability is a missing authorization flaw that allows an attacker to perform actions normally reserved for privileged users, such as creating, modifying, or deleting recipe cards. The attacker can therefore manipulate site content or expose sensitive data, potentially compromising the site’s integrity and confidentiality.
Affected Systems
WordPress sites installing WPZOOM Recipe Card Blocks for Gutenberg & Elementor plugin version 3.4.8 or earlier are affected. The flaw exists across all releases up to and including 3.4.8, meaning any site still using these versions is exposed.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of <1% suggests a low likelihood of exploitation at present. The vulnerability is not catalogued in CISA KEV, implying no known public exploitation. An attacker would first need to identify a site running a vulnerable plugin version and then bypass normal access controls, likely by using authenticated requests or exploiting existing administrative privileges. Until an update is applied, monitoring for new exploitation attempts is advised.
OpenCVE Enrichment