Impact
Missing authorization in the WordPress Starter Templates plugin causes authenticated users to gain access to administrative functions that should be restricted. The flaw is an improper capability check, classified as CWE‑862. An attacker can modify or delete template settings, potentially compromising site content and configuration.
Affected Systems
The affected product is the WordPress Starter Templates plugin distributed by Brainstorm Force. Installations of version 4.7.7 or earlier are vulnerable. Starting with version 4.7.8 the issue has been fixed.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate severity. EPSS is not available and the vulnerability is not listed in CISA KEV, so the likelihood of exploitation remains undetermined. The description suggests missing authorization for plugin settings, so it is inferred that an authenticated user with normal login credentials could exploit the flaw to modify template settings. No evidence of remote code execution or denial of service is indicated.
OpenCVE Enrichment