Impact
The B Slider- Gutenberg Slider Block for WP plugin suffers from a missing capability check in the activated_plugin function, allowing authenticated users with Subscriber role or higher to install arbitrary plugins. This flaw can be leveraged to execute remote code on the WordPress site, representing a serious confidentiality, integrity, and availability threat. The weakness is classified as CWE-862, reflecting an authorization failure.
Affected Systems
The vulnerability affects the bSlider – Create Responsive Image, Post, Product, and Video Sliders plugin supplied by bplugins. All versions up to and including 1.1.30 are impacted; newer releases beyond 1.1.30 contain the fix.
Risk and Exploitability
The likely attack vector is an authenticated user with Subscriber role or higher in a WordPress installation exploiting the missing capability check in the activated_plugin function to install malicious plugins. With a CVSS score of 8.8, this flaw allows remote code execution once the attacker has legitimate credentials. The EPSS score of <1% indicates that exploitation activity is currently low, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, any subscriber or higher role user can potentially install and activate harmful plugins, posing a significant threat to confidentiality, integrity, and availability.
OpenCVE Enrichment
EUVD