Impact
The vulnerability is a missing authorization flaw that allows attackers to bypass correctly configured access control levels. This enables unauthorized users to access, create, or modify resources that should be restricted, potentially exposing sensitive portfolio data or altering content. The weakness falls under CWE‑862, which identifies missing or incomplete authorization checks.
Affected Systems
The issue affects the HomeFix Elementor Portfolio plugin by designthemes in all releases from the first version up to and including 1.0.1. No newer versions are listed as affected.
Risk and Exploitability
With a CVSS score of 5.3, the flaw poses moderate severity, and an EPSS score of less than 1% indicates a low probability of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, through the plugin's web interface, and requires no special credentials; attackers can craft requests that bypass the plugin’s access checks to read or alter restricted data.
OpenCVE Enrichment