Missing Authorization Vulnerability in Slider a SlidersPack by Essential Plugin
CVE-2022-46845

5.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
9 December 2025

What is CVE-2022-46845?

An access control issue in Slider a SlidersPack plugin allows attackers to bypass authorization checks, leading to potential exposure of restricted functionalities. The vulnerability arises from an incorrect configuration of access control security levels, impacting versions before 2.3. It's crucial for users to update their plugins to the latest version to mitigate the risks associated with this vulnerability.

Affected Version(s)

Slider a SlidersPack < 2.3

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Cat (Patchstack Bug Bounty Program)
.