Impact
The vulnerability is a missing authorization flaw in the Ays Pro Image Slider by Ays plugin (ays-slider). The flaw allows an attacker to bypass configured access control security levels and perform unauthorized actions on the web application, potentially exposing or modifying protected data. This broken access control is identified as CWE-862 (Missing Authorization).
Affected Systems
Affected systems include installations of the Ays Pro Image Slider by Ays plugin with version 2.7.1 or older; any WordPress site that has the plugin enabled can be impacted regardless of theme or other plugins.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of <1% suggests that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. Attackers would likely need to target the plugin’s administrative endpoints, either from within the WordPress environment or by users with certain permissions. No public exploit has been documented, but the missing authorization could enable a range of unauthorized operations.
OpenCVE Enrichment