Impact
The WordPress Style Kits plugin (versions up to 2.6.5) has a broken access control flaw that allows users with subscriber level privileges to view or modify style kits belonging to other subscribers. This flaw does not provide remote code execution or privilege escalation beyond the plugin’s scope but may expose proprietary design information and allow unwanted alterations to site styling. The weakness is assignable to CWE-862.
Affected Systems
AnalogWP Style Kits plugin, all releases up to and including version 2.6.5.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity vulnerability. No EPSS data is available, so the likelihood of exploitation cannot be quantified from this metric. The vulnerability is not currently listed in the CISA KEV catalog. Based on the description, the attack path requires an authenticated subscriber account; the attacker can access the plugin’s front‑end or API endpoints to read or change other users’ style kits. No special environment or pre‑conditions beyond normal WordPress operation are documented, and there is no evidence of exploitation from unauthenticated users.
OpenCVE Enrichment