Impact
The Shoppable Images Lite plugin for WordPress versions 1.3 and earlier contains a flaw that allows users with the subscriber role to bypass role checks and perform privileged actions that should be restricted to administrators. This broken access control can let a non‑admin user manipulate shop settings or access administrative functions, resulting in unauthorized configuration changes and potential data exposure.
Affected Systems
The vulnerability is present in the Shoppable Images Lite WordPress plugin produced by studiowombat, affecting all releases up to and including 1.3.
Risk and Exploitability
The CVSS score of 4.3 indicates a low to moderate impact. No EPSS score is available, and the issue is not listed in the CISA KEV catalog. The flaw is exploitably through the plugin’s administration interface, where the lack of proper role validation permits subscriber accounts to invoke privileged actions via crafted requests. Because the attack vector requires a valid login, it is considered a local or authenticated external vulnerability rather than a remote unauthenticated exploit.
OpenCVE Enrichment