Impact
The Homey theme for WordPress is vulnerable to CSRF because the homey_verify_user_manually function does not perform proper nonce validation. An unauthenticated attacker can send a forged request that an administrator executes, causing the system to update a user’s verification status. This flaw allows the attacker to grant themselves or another user verified privileges without legitimate credentials. The weakness is recorded as CWE‑352.
Affected Systems
The Homey theme developed by Fave Themes is affected in all releases up to and including 2.4.3 when used on WordPress sites. No specific WordPress core versions are listed, so any installation of the theme in that range is vulnerable.
Risk and Exploitability
The vulnerability carries a CVSS score of 4.3, indicating moderate severity. The EPSS score is below 1 %, showing low current exploitation likelihood, and the flaw is not listed in the CISA KEV catalog. Exploitation requires an attacker to craft a forged request and persuade a site administrator to click a link, typically via phishing or a malicious embed. Because the flaw relies on missing nonce checks, no elevated access is required beyond the attacker’s ability to initiate a request.
OpenCVE Enrichment
EUVD