Impact
The vulnerability is a missing authorization flaw in the Table Block by RioVizual WordPress plugin. Incorrectly configured access control security levels allow an attacker to bypass legitimate permission checks and gain unrestricted access to the plugin’s functionality. This can result in the exposure or manipulation of data handled by the plugin and potentially the underlying WordPress installation.
Affected Systems
All installations of Table Block by RioVizual with versions up to and including 3.0.0 are affected. The vulnerability does not specify a particular affected operating system, browser, or configuration beyond the plugin version range.
Risk and Exploitability
The CVSS score of 4.3 indicates a low severity impact, and the EPSS score of less than 1% suggests a very low likelihood of exploitation in the wild. The plugin is not listed in the CISA KEV catalog, further implying limited exploitation activity. The flaw is most likely exploitable through the web interface of a WordPress site that hosts the vulnerable plugin; an attacker would need to target a site where the plugin is installed and exploit the lack of proper authorization checks. No specialized prerequisites are indicated beyond access to the vulnerable URL path provided by the plugin.
OpenCVE Enrichment