Impact
The vulnerability is a missing authorization flaw in WordPress Re Gallery plugin versions up to 1.18.9, allowing attackers to bypass role restrictions. This could expose or allow unauthorized modification of plugin or site data that is normally protected by access controls.
Affected Systems
Any WordPress site that uses the Re Gallery plugin at version 1.18.9 or earlier is affected. The impact applies to users who can interact with the plugin interface, including those with limited or no administrative privileges.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is below 1 %, suggesting a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The flaw stems from incorrectly configured access controls in the plugin’s web interface; no available public exploits are reported as of the data provided.
OpenCVE Enrichment