Impact
The Capella WordPress theme contains an unauthenticated privilege escalation flaw that lets an attacker elevate privileges on a site using any version up to 2.5.5. This weakness is categorized as CWE-266, indicating improper access control.
Affected Systems
Site owners using WordPress with ThemeGoods Capella theme version 2.5.5 or earlier are vulnerable. The flaw affects the Capella theme from ThemeGoods, supplying the frontend interface for WordPress sites.
Risk and Exploitability
The flaw can be triggered by any visitor, with no authentication required, giving an attacker the potential to assume administrative capabilities. The CVSS score of 9.8 signals a critical severity, and while the EPSS score is not available, the high impact rating suggests that exploitation is likely if the site remains on an affected version. The vulnerability is not listed in CISA KEV, but the combination of high severity and lack of restrictions makes it a priority to address.
OpenCVE Enrichment