Impact
The Art Theme for WordPress contains a missing capability check on the AJAX endpoint "arttheme_theme_option_restore" in all versions up to and including 3.12.2.3. This flaw allows any authenticated user with subscriber-level access or higher to trigger the deletion of theme options, which can alter site appearance and disrupt theme functionality. The vulnerability does not provide code execution or broader system compromise, but it enables destructive configuration changes that degrade user experience.
Affected Systems
SeaTheme:Art Theme for WordPress versions 3.12.2.3 and earlier are vulnerable. Users running any release up to 3.12.2.3 should update or mitigate to remove the risk.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate impact, while the EPSS score of less than 1% suggests a low probability of exploitation. The issue is not listed in the CISA KEV catalog. Exploitation requires the attacker to be authenticated at the subscriber level or higher and to access the unauthenticated AJAX endpoint, making the attack remote but credential-dependent.
OpenCVE Enrichment
EUVD