Impact
Missing authorization in the TS Demo Importer plugin allows a remote attacker to bypass access controls and perform actions without proper authentication, as defined by CWE-862. This vulnerability can enable an attacker to read, modify, or delete data associated with the plugin or adjacent site content, potentially compromising confidentiality and integrity.
Affected Systems
Affected systems include the WordPress TS Demo Importer plugin by themeshopy, specifically versions up to and including 0.1.3. No other version details are provided and newer releases may address the issue.
Risk and Exploitability
The CVSS base score of 5.4 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of successful exploitation. The vulnerability is not listed in the CISA KEV catalog. Likely exploitation would involve sending crafted requests to the plugin’s endpoints without needing prior authentication, using the fact that authorization checks are missing.
OpenCVE Enrichment