Impact
The vulnerability stems from a missing authorization check in the WordPress Breakdance plugin. When security levels are incorrectly configured, the plugin fails to enforce proper access controls, allowing users to interact with functions that should be restricted. This flaw can lead to unauthorized viewing or modification of content, form settings, or other sensitive data managed through the plugin, potentially compromising the integrity and confidentiality of the website’s configuration.
Affected Systems
The issue targets the Soflyy Breakdance plugin for WordPress, affecting every installation of the plugin that is running any version prior to 2.7. Any WordPress site that has installed Breakdance 2.6.1 or earlier is susceptible.
Risk and Exploitability
The CVSS base score of 7.5 indicates a high severity of exploitation. EPSS data is not available, and the vulnerability is not yet listed in CISA's KEV catalog, suggesting no publicly known exploits to date. The likely attack vector requires an authenticated user with at least some level of access to the WordPress admin interface; such a user could exploit the configuration flaw to gain unauthorized control over plugin functions. The exploitation effort is relatively low, given that the flaw arises from missing ACL checks rather than a complex sequence of inputs.
OpenCVE Enrichment