Impact
Missing authorization in the Gutenverse News – Advanced News Magazine Blog Gutenberg Blocks Addons plugin allows an attacker to perform actions they should not be permitted to. The flaw violates the access control requirement defined in CWE‑862 and could enable unauthorized reading or modification of site content, leading to potential loss of confidentiality and integrity of posts and media.
Affected Systems
The vulnerability affects Jegstudio’s Gutenverse News – Advanced News Magazine Blog Gutenberg Blocks Addons plugin, versions from the initial release through 3.0.2. Users with this plugin installed on any WordPress site are at risk unless upgraded to a newer, fixed release.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, while the EPSS score of less than 1% suggests that exploitation is currently uncommon. The vulnerability is not listed in CISA KEV. Attackers would likely need some level of authenticated access—such as an admin or author account—to exploit the broken access control, though the exact conditions are not explicitly stated in the advisory and are inferred from the description of incorrectly configured security levels.
OpenCVE Enrichment