Impact
The vulnerability arises because the History Timeline plugin does not enforce proper authorization on its internal endpoints, allowing any user to access restricted functionality or data. This missing authorization can lead to unauthorized disclosure of timeline entries or unintended manipulation of content, an issue categorized under CWE-862.
Affected Systems
The issue affects the themesawesome History Timeline plugin (Timeline Awesome) version 1.0.6 and all earlier releases that are commonly used across WordPress installations.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate impact while the EPSS score of < 1% reflects a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, implying no known public exploit. The likely attack vector is through the plugin’s web interface, requiring no special network conditions or elevated privileges, and can be performed by unauthenticated or minimally privileged users.
OpenCVE Enrichment