Impact
The Simple Theme Changer plugin contains missing capability checks on the user_theme_admin, display_method_admin, and set_change_theme_button_name Ajax actions in all versions up to 1.0. This flaw allows an authenticated attacker who is a subscriber or higher to modify the plugin's settings, potentially changing the site's theme or related display options. The weakness is a missing permission check, classified as CWE‑862.
Affected Systems
WordPress sites using the Simple Theme Changer plugin by darendev, versions 1.0 and earlier.
Risk and Exploitability
The CVSS score of 4.3 indicates low to moderate severity. The EPSS score of less than 1% suggests a very low likelihood of exploitation, and the vulnerability is not listed in CISA's KEV catalog. Attackers need to be authenticated and possess at least subscriber privileges, after which they can issue Ajax requests to the vulnerable actions.
OpenCVE Enrichment