Impact
The vulnerability is a missing authorization flaw in the Xpro Addons For Beaver Builder – Lite WordPress plugin, enabling exploitation of incorrectly configured access control security levels. The issue permits attackers to activate or modify plugin features and settings that should be restricted, leading to unauthorized access to privileged functions within the WordPress site.
Affected Systems
Affected systems are installations of Xpro Addons For Beaver Builder – Lite with any version up to and including 1.5.6. The issue exists from the earliest available version through 1.5.6, meaning all sites using the plugin within this range are at risk.
Risk and Exploitability
The CVSS score of 5.3 points to moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through the web interface of the WordPress site, requiring an attacker to send crafted HTTP requests to plugin endpoints. Although no remote code execution is required, the flaw grants privileges beyond those intended by normal user roles.
OpenCVE Enrichment