Impact
Missing Authorization in the Smart Product Viewer plugin allows attackers to exploit incorrectly configured access control rules, enabling unauthorized access to content or configuration data managed by the plugin.
Affected Systems
Vulnerable versions of the Smart Product Viewer plugin from topdevs include all releases up to and including 1.5.4. Site owners using any of these versions—regardless of the overall WordPress environment—are at risk unless they upgrade or apply mitigations.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score of less than 1% reflects a very low expected exploitation probability. The vulnerability is not currently listed in the CISA KEV catalog. Based on the description, it is inferred that the likely attack vector is a remote web request to the plugin’s endpoints, though specific exploitation details are not disclosed.
OpenCVE Enrichment