Impact
The Cardealer WordPress theme contains a missing capability check in its save_settings function, allowing any authenticated user with the Subscriber role or higher to modify the theme options. This flaw enables the attacker to change the default user role, effectively escalating privileges to higher roles such as Administrator and granting unrestricted access to the site.
Affected Systems
ThemeMakers Card Dealer Automotive WordPress Theme – Responsive, versions up to and including 1.6.4. WordPress sites using this theme are affected. The theme is available on ThemeForest under the 8574708 identifier.
Risk and Exploitability
With a CVSS score of 8.8 the vulnerability is considered High. The EPSS score is < 1%, indicating a low probability that it will be actively exploited at present. The vulnerability is not listed in the KEV catalog. An attacker requires a valid authenticated session with at least Subscriber access; from there the flaw can be leveraged by sending a request to the settings endpoint to change role assignments. The lack of a required high admin capability makes the exploit straightforward for any authenticated user.
OpenCVE Enrichment
EUVD