Impact
A missing authorization check in the famethemes OnePress WordPress theme allows an attacker to perform actions that should be limited to privileged users. The weakness is classified as CWE‑862, broken access control. The vulnerability can lead to unauthorized configuration changes or exposure of sensitive information within the WordPress site, potentially compromising site integrity and confidentiality.
Affected Systems
WordPress sites running the famethemes OnePress theme version 2.3.11 or earlier are affected. The vulnerability applies to all releases from the first available version up to and including 2.3.11. Users of older or newer themes are not impacted.
Risk and Exploitability
The CVSS score of 4.3 indicates a medium baseline impact, while the EPSS score of less than 1% suggests a very low probability of exploitation at this time. The issue is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is an authenticated attacker who can access theme management interfaces gaining elevated permissions. No additional exploitation prerequisites are stated.
OpenCVE Enrichment
EUVD