Impact
The vulnerability is a missing authorization flaw (CWE‑862) in the WordPress plugin Dashboard Welcome for Beaver Builder. Legitimate users who are logged into the site can reach plugin‑related pages that are intended for administrators only, potentially exposing or modifying site content without proper permission checks. This flaw does not directly grant code execution but can lead to unauthorized data access or configuration changes.
Affected Systems
The issue affects the IdeaBox Creations Dashboard Welcome for Beaver Builder plugin versions up to and including 1.0.8. Any WordPress installation that has this plugin installed and has not been updated to a newer release is vulnerable.
Risk and Exploitability
The EPSS score is below 1 %, indicating a very low likelihood of exploitation at present, and the flaw is not listed in the CISA KEV catalog. However, because the flaw allows lower‑privilege users to view or modify protected plugin content, the potential impact on confidentiality and availability remains significant. An attacker would first need to authenticate to the site and then request a plugin page; the lack of authorization checks would allow access to administrative features.
OpenCVE Enrichment