Impact
This vulnerability is a missing authorization flaw that permits an attacker to bypass incorrectly configured access control security levels within the PickPlugins Testimonial Slider plugin. By exploiting this gap, an unauthenticated user could modify testimonial entries, alter display settings, or delete content, compromising the confidentiality, integrity, and potential availability of the website’s testimonial section.
Affected Systems
The affected product is PickPlugins Testimonial Slider, versions ranging from the earliest releases through version 2.0.15. Any WordPress site running those plugin versions is vulnerable unless it has been patched or the plugin removed.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while an EPSS score of less than 1% shows a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a web-based request to the plugin’s administrative interface or exposed endpoints, which does not require authentication credentials.
OpenCVE Enrichment