Impact
The vulnerability is a missing authorization flaw in the Image Caption Hover Pro plugin for WordPress. It allows attackers to access and modify image captions that should be restricted to privileged users. The weakness is a classic broken access control (CWE‑862), enabling unauthorized users to read or alter protected data and potentially compromise the integrity of the website.
Affected Systems
Affected systems are installations of WebCodingPlace Image Caption Hover Pro with versions earlier than 20.0. The issue spans all releases from the earliest available version up to, but not including, 20.0, as the plugin lacks proper authentication checks in these releases.
Risk and Exploitability
The CVSS base score of 5.4 reflects a moderate impact, and the EPSS score of less than 1 % indicates a low likelihood of widespread exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers would likely need web access to the WordPress site and may exploit incorrectly configured user roles; however, detailed prerequisites are not documented, so the analysis is that the flaw could be exploited remotely via the web interface.
OpenCVE Enrichment