Impact
Missing Authorization in the Averta LTD Shortcodes and extra features for Phlox theme auxin‑elements allows exploitation of incorrectly configured access control security levels. This flaw permits an attacker to exercise functionality beyond intended permissions, potentially exposing sensitive data or enabling unauthorized actions within the WordPress site. The vulnerability is classified as CWE‑862 and does not involve remote code execution, but grants elevated privileges that could be leveraged for further attacks if combined with other weaknesses. The issue affects plugin versions from the initial release through 2.17.22.
Affected Systems
The vulnerability affects the Averta LTD Shortcodes and extra features for Phlox theme auxin‑elements plugin, from its initial release through version 2.17.22. All installations running these or earlier versions are potentially exposed and need updating.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity. The EPSS score of less than 1% suggests a low likelihood of exploitation at this time, and the vulnerability is not currently listed in the CISA KEV catalog. Likely, an attacker would trigger the flaw by accessing plugin‑provided shortcode endpoints or administrative interfaces without proper permission checks. The attack vector is inferred to be through HTTP requests to the plugin’s endpoints, and the exploit would not require an existing authenticated session, given the missing authorization checks.
OpenCVE Enrichment