Impact
The CVE describes a broken access control flaw that allows an attacker to manipulate WP Bannerize Pro configuration settings without proper authorization. This unauthorized access could enable the creation, modification, or deletion of banner content on the host WordPress site, potentially resulting in defacement, brand integrity compromise, or denial of service to legitimate banner displays.
Affected Systems
All installations of the WordPress WP Bannerize Pro plugin produced by gfazioli, version 1.11.0 or earlier, are vulnerable. Any WordPress site that has the plugin installed and has not updated beyond 1.11.0 is potentially exposed.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact, and the EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is likely through web-based plugin management interfaces where proper authorization checks are missing, allowing attackers—potentially unauthenticated—to alter banner settings. The associated weakness is identified as CWE-862, broken access control.
OpenCVE Enrichment