Impact
The vulnerability is a missing authorization flaw (CWE-862) that allows users without sufficient privileges to access protected features of the Custom Layouts – Post + Product grids made easy plugin. By exploiting incorrectly configured security levels, attackers can view or modify content managed by the plugin, effectively escalating their privileges within the WordPress site.
Affected Systems
WordPress installations that include Code Amp Custom Layouts – Post + Product grids made easy plugin versions 1.4.12 or earlier are affected. The flaw exists in all releases up to and including the identified maximum version; no patch or mitigation is provided specific to earlier releases.
Risk and Exploitability
With a CVSS score of 4.3, the vulnerability is considered of moderate severity. The EPSS score of less than 1% indicates a very low probability of exploitation in the immediate future, and it is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector involves interacting with the plugin’s administrative interface or exposed endpoints where authentication checks are insufficient.
OpenCVE Enrichment