Impact
The Hello Plus plugin for WordPress fails to verify that a user is authorized to perform template activation actions. Because of this oversight, authenticated users with Contributor-level access can publish new Hello+ header/footer templates and can also draft templates that are currently owned by higher‑privileged users. This can allow an attacker to insert malicious code or deface the site without permission, representing a clear authorization bypass flaw (CWE-862).
Affected Systems
WordPress installations running the Hello Plus plugin on version 1.7.7 or earlier are affected. The vendor appears to be Elementor (elemntor:Hello Plus) and any site that has this plugin enabled could be vulnerable if it has Contributor or higher users.
Risk and Exploitability
The vulnerability has a CVSS score of 5.4, indicating a moderate severity. No EPSS score is available, and the CVE is not listed in the CISA KEV catalog, suggesting it has not yet been widely exploited. Since the flaw requires an authenticated Contributor account, an attacker needs only to log in with such credentials, which are often granted to legitimate content editors. Once authenticated, the attack can be carried out locally on the site without additional privileges, making the risk moderate but relevant for sites that keep many Contributor users.
OpenCVE Enrichment