Impact
The vulnerability is a missing authorization flaw that permits any user to bypass built‑in security checks within the WeDesignTech Portfolio plugin. An attacker can exploit this broken access control to view or modify data managed by the plugin, potentially exposing sensitive portfolio content or altering user functionality. This weakness maps to CWE‑862, which describes situations where access permissions are improperly enforced.
Affected Systems
The issue affects the designthemes WeDesignTech Portfolio WordPress plugin up through version 1.0.2. Any installation that has not been upgraded past that point is susceptible.
Risk and Exploitability
With a CVSS score of 5.3, the risk is moderate, and an EPSS score of less than 1% indicates a low likelihood of active exploitation at this time. The vulnerability is not listed in CISA KEV. The most probable attack vector is remote, via the web interface, by leveraging inaccessible plugin endpoints that lack proper permission checks. An attacker would need only a web browser and knowledge of the plugin’s URLs to gain unauthorized access.
OpenCVE Enrichment