Impact
The vulnerability stems from a missing authorization check that enables exploitation of incorrectly configured access control security levels within the QuadLayers TikTok Feed plugin. This flaw allows an attacker to bypass intended restrictions and gain unauthorized access to administrative or content‑management functions of the plugin. The weakness is categorized as CWE‑862.
Affected Systems
All released versions of the QuadLayers TikTok Feed plugin for WordPress up to and including 4.6.5 are affected. The vulnerability exists from the earliest known release through 4.6.5; newer releases beyond 4.6.5 are not impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of <1% suggests low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is likely remote, with an attacker able to send crafted requests to the plugin’s endpoints to exploit the missing authorization; the specific need for authentication depends on the site’s configuration, a point inferred from the description of incorrectly configured security levels.
OpenCVE Enrichment