Impact
The vulnerability is a missing authorization flaw in the Quick Interest Slider plugin for WordPress that allows an attacker to exploit incorrectly configured access control settings. This defect enables users who do not normally have permission to reach privileged plugin functionality and potentially alter or view content that should be restricted. The primary impact is an access control bypass that can lead to unauthorized manipulation of the plugin’s settings or data.
Affected Systems
Graham Quick Interest Slider plugin, all versions from the earliest available through 3.1.7 inclusive, is affected by the missing authorization check. Users of any of these versions are at risk until the plugin is upgraded or otherwise mitigated.
Risk and Exploitability
The vendor’s CVSS score of 5.3 categorizes the flaw as moderate severity, and the EPSS score of less than 1% indicates a very low probability of exploitation in the current threat landscape. The vulnerability is not listed in the CISA KEV catalog, reducing the likelihood of widespread or known attacks. Based on the description, it is inferred that exploitation occurs via the WordPress web interface, where an attacker with sufficient access could call the plugin’s functionality without proper authorization checks.
OpenCVE Enrichment