Impact
The Block Slider plugin contains a missing authorization flaw that permits attackers to exploit incorrectly configured access control settings. This weakness, identified as CWE-862, allows unauthorized users to perform actions that should be restricted to privileged roles.
Affected Systems
WordPress sites that have the Block Slider plugin installed and are running any version up to and including 2.2.3. The plugin is developed by Munir Kamal and is commonly embedded as a block within the WordPress editor.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the probability of exploitation is very low, as indicated by an EPSS score of less than 1% and the absence of the vulnerability from the CISA KEV catalog. Nonetheless, if an attacker gains entry to the site and sufficiently low permissions, the flaw could be used to manipulate or create blocks beyond intended scope, potentially leading to unauthorized content changes or site‑wide configuration modifications.
OpenCVE Enrichment