Impact
The Eco Nature WordPress Theme is vulnerable because the Ajax handler 'cmsmasters_hide_admin_notice' lacks a capability check. An authenticated user with the Subscriber role or higher can invoke this handler to change theme options. The attacker can set values that cause fatal errors or enable unwanted features, resulting in a denial of service for legitimate users. The vulnerability does not expose sensitive data but allows modification of site configuration that can disrupt normal operation.
Affected Systems
Any WordPress installation using cmsmasters’ Eco Nature – Environment & Ecology WordPress Theme version 2.0.4 or earlier is affected. The issue exists in all released builds up to and including that version. Sites that are still running these releases with at least a Subscriber‑level user account are at risk.
Risk and Exploitability
The CVSS score of 8.1 categorizes the flaw as high severity, and the EPSS score of less than 1% suggests that exploitation is currently unlikely. The attack requires that the attacker already has authenticated access to the site; no elevated server privileges are needed. Because the flaw is not listed in the CISA KEV catalog and no public exploits are confirmed, the threat is primarily to availability rather than confidentiality or integrity. However, if a malicious user gains the necessary role, they could disrupt the site or enable unwanted registration settings.
OpenCVE Enrichment
EUVD