Impact
The vulnerability is a missing authorization flaw in the topdevs.net Simple Like Page plugin that permits attackers to exploit incorrectly configured access control settings. This flaw can allow a user to perform operations within the plugin that they should not be permitted to execute, potentially leading to unauthorized manipulation or disclosure of content handled by the plugin.
Affected Systems
Vendors and products affected include topdevs.net’s Simple Like Page plugin. Versions from the initial release through and including 1.5.3 are vulnerable; any distribution of the plugin prior to or equal to 1.5.3 remains at risk.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, while the EPSS score of less than 1% suggests a low but nonzero probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a remote exploitation via the plugin’s web interface or API endpoints, inferred from the fact that the flaw relates to misconfigured access control in a web‑based plugin.
OpenCVE Enrichment