Impact
The vulnerability is a missing authorization flaw in the YITH Slider for page builders plugin. An attacker can manipulate the plugin’s functionality or data access without proper role checks. The flaw is classed as CWE‑862 and can potentially lead to unauthorized modification or viewing of slider content, compromising data integrity and confidentiality within the WordPress site.
Affected Systems
Affected product is YITHEMES YITH Slider for page builders for all releases up to and including 1.0.11. Any WordPress site that has this plugin installed in those versions is vulnerable.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate risk. The EPSS score is less than 1%, suggesting a low probability of exploitation at this time, and the vulnerability is not listed in CISA KEV. Attackers would need to craft requests to the plugin’s endpoints; given the lack of access controls, web attackers with path to the site can execute unauthorized actions. The flaw can be applied remotely via crafted web requests, and the exact prerequisites are inferred to be the presence of the plugin on a publicly accessible WordPress installation.
OpenCVE Enrichment