Impact
The vulnerability is a missing authorization flaw in the Houzez theme for WordPress. During normal use, privileged users or attackers who succeed in gaining limited access to the site can exploit this weakness to perform actions that should be restricted, potentially accessing data or performing operations beyond their intended scope. The weakness is classified as access control failure.
Affected Systems
WordPress installations using the Houzez theme, versions up through 3.4.0. Any site that has the Houzez theme enabled and is running a version equal to or older than 3.4.0 is at risk.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity vulnerability, while the EPSS score of < 1% suggests a low probability of exploitation at present. The issue is not listed in the CISA KEV catalog. Based on the description, it is inferred that exploitation would require some level of authenticated access within the WordPress environment, such as a compromised administrator or editor account, to leverage the broken access control.
OpenCVE Enrichment
EUVD