Impact
This vulnerability is a missing authorization flaw in the merkulove Scroller WordPress plugin that allows users to exploit incorrectly configured access control settings. An attacker who can gain access to the plugin’s restricted functions can perform actions intended only for privileged users, potentially modifying content, settings, or other protected data. The weakness is categorized as a classic broken access control (CWE‑862).
Affected Systems
WordPress sites running the merkulove Scroller plugin version 2.0.2 or earlier are affected. No lower bound is specified, indicating that all published releases up to the listed maximum suffer from the flaw.
Risk and Exploitability
The CVSS score of 5.4 classifies this issue as moderate severity, while the EPSS score of less than 1% indicates a very low exploitation probability at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through WordPress administrative or plugin endpoints that rely on the plugin’s internal access checks; an attacker with sufficient permissions or access to mis‑configured security levels could abuse the flaw, but the actual exploitation would require the plugin’s functions to be exposed to non‑privileged users.
OpenCVE Enrichment