Impact
This vulnerability is a broken access control flaw in the AnalogWP Style Kits WordPress plugin versions up to and including 2.6.5. An attacker who obtains a contributor or higher privilege can create, modify, or delete style kits that should be restricted. The flaw, identified as CWE‑862, allows an attacker to alter the visual presentation of a WordPress site, resulting in unauthorized changes to the site’s appearance.
Affected Systems
The affected product is the AnalogWP Style Kits WordPress plugin, specifically all editions with versions 2.6.5 and earlier. No other components or plugins are listed as impacted.
Risk and Exploitability
The CVSS score of 6.3 denotes medium severity, and the EPSS score of < 1 % indicates a very low likelihood of exploitation at present. The issue is not listed in the CISA KEV catalog. The attacker must be authenticated with at least contributor-level rights, and the most likely attack vector is through the plugin’s authenticated web interface. Based on the description, it is inferred that the exploitation path involves using the plugin’s settings or administration pages to manage style kits without adequate permission checks.
OpenCVE Enrichment