Impact
The Homey WordPress theme is vulnerable because its homey_reservation_del() function lacks a capability check, allowing authenticated users with Subscriber-level access or higher to delete any reservation or post. This enables attackers to erase booking data, potentially causing loss of revenue, disrupting service, and eroding user trust. The flaw is a classic example of missing authorization, identified as CWE-862.
Affected Systems
The vulnerability affects the Homey booking and rentals WordPress theme from Fave Themes, versions 2.4.4 and earlier. Any WordPress site installing these theme versions is susceptible.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score is below 1%, suggesting low likelihood of exploitation. Attacks require a valid authenticated account with Subscriber-level permissions or higher, and exploitability hinges on the theme’s deletion function. The vulnerability is not listed in CISA’s KEV catalog, implying no known widespread exploitation at the time.
OpenCVE Enrichment
EUVD