Impact
An insecure direct object reference flaw in the Brainstorm Force Starter Templates WordPress plugin allows an attacker to manipulate internal identifiers that reference template records. The flaw, classified as CWE‑639, permits access to, or alteration of, template data belonging to other users or templates, thereby compromising confidentiality and integrity of the site’s content.
Affected Systems
WordPress sites that have the Starter Templates plugin from Brainstorm Force installed at version 4.7.5 or earlier are affected. Any site running this plugin, regardless of the underlying theme, and that has not upgraded to 4.7.6 or later is vulnerable.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity, while an EPSS score of less than 1% suggests a very low but non‑zero probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, indicating no large‑scale incidents have been reported. Based on the description, the likely attack vector is web‑based; an attacker may exploit the IDOR through the plugin’s HTTP endpoints, potentially requiring only basic user permissions or no credentials at all, depending on the plugin’s access controls.
OpenCVE Enrichment