Impact
The vulnerability is a missing authorization flaw in the Xpro Addons For Beaver Builder – Lite WordPress plugin, allowing an attacker to exploit incorrectly configured access control security levels. Key detail from vendor description: "Missing Authorization vulnerability" reveals that this broken access control (CWE-862) permits users to activate or modify plugin features and settings that should be restricted. The primary impact is the compromise of data integrity and potential expansion of privileges within the WordPress site.
Affected Systems
Affected systems are installations of Xpro Addons For Beaver Builder – Lite with any version up to and including 1.5.6. The issue exists from the earliest available version through 1.5.6, meaning all sites using the plugin within this range are at risk.
Risk and Exploitability
The CVSS score of 5.3 points to moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through the web interface of the WordPress site, requiring an attacker to send crafted HTTP requests to plugin endpoints. Although no remote code execution is required, the flaw grants privileges beyond those intended by normal user roles.
OpenCVE Enrichment