Impact
WordPress plugin Codeless Slider Templates suffers from missing authorization checks that allow users to access administrative functionality without proper access control.
Affected Systems
Vulnerable versions of the Codeless Slider Templates plugin for WordPress numbered 1.0.3 and earlier are affected. Users running those versions on a WordPress site should consider them compromised until a fix is applied.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. EPSS is below 1%, suggesting a low exploitation probability at the time of this analysis, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via web requests to the plugin’s endpoints, which are accessible without proper authentication checks. An attacker who can reach those endpoints could invoke privileged functionality that should have been restricted to authorized users.
OpenCVE Enrichment