Impact
The LottieFiles WordPress plugin has a missing authorization flaw that allows an attacker who can reach the plugin’s endpoints to bypass configured access control levels. Classified as CWE‑862, the vulnerability permits an attacker to perform actions that should be restricted to privileged users, potentially altering or managing site media content through the plugin’s interface.
Affected Systems
Any WordPress site running the LottieFiles plugin up to and including version 3.0.0 is affected. The plugin is distributed under the LottieFiles brand, and all releases in the range from the initial release through version 3.0.0 contain the flaw.
Risk and Exploitability
The CVSS score of 7.3 indicates a high severity, while the EPSS score of 1% suggests a low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote via the web interface; an attacker needs the ability to access the plugin’s administrative URLs and does not require any special conditions beyond normal WordPress site access.
OpenCVE Enrichment