Impact
The vulnerability is a missing authorization check in the ThemeFusion Fusion Builder WordPress plugin. This flaw allows exploitation of incorrectly configured access control security levels, leading to a broken access control weakness classified as CWE-862.
Affected Systems
All WordPress sites that use the Fusion Builder plugin version earlier than 3.15.0 are affected. The vulnerability exists in all releases from unspecified starting versions up to, but not including, 3.15.0.
Risk and Exploitability
The CVSS score of 6.3 indicates medium severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker could interact with the plugin’s web interface to gain unauthorized access to protected resources.
OpenCVE Enrichment