Impact
The vulnerability is a missing authorization flaw in the CryoutCreations Serious Slider WordPress plugin. Because access control checks are incorrectly implemented, a user with sufficient privileges can access the plugin’s configuration interface and alter slider settings, change display content, or otherwise modify the website’s appearance and content. The flaw is classified as a broken access control weakness (CWE‑862).
Affected Systems
Any WordPress site that uses CryoutCreations Serious Slider version 1.2.7 or earlier is affected. The plugin is installed through the WordPress plugin repository under the CryoutCreations vendor.
Risk and Exploitability
The reported vulnerability carries a CVSS score of 4.3, indicating moderate severity. EPSS is less than 1 %, so the probability of exploitation is low, and the vulnerability is not listed in the CISA KEV catalog. The likely attack path involves an authenticated WordPress user with elevated privileges navigating to the slider’s administrative page, where the lack of proper checks allows configuration changes. Because it requires valid credentials, the risk is primarily to sites whose user accounts have sufficient permissions.
OpenCVE Enrichment