Impact
The Litho Addons plugin for WordPress contains missing authorization checks, which is a broken access‑control issue (CWE‑862). This flaw allows a user who should not have administrative rights to reach privileged plugin functions and modify settings that influence site appearance and functionality. The potential impact is privilege escalation within the plugin’s scope, enabling unauthorized configuration changes.
Affected Systems
The affected product is the Litho Addons plugin distributed by themezaa. All released versions up to and including 3.5 are vulnerable. Sites that have installed any version of the plugin in that range are susceptible.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. The EPSS score of less than 1% suggests a very low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be within the WordPress web application, typically requiring interaction with the admin dashboard or an authenticated user context to invoke the vulnerable plugin functions.
OpenCVE Enrichment