Impact
This vulnerability is a missing authorization flaw in the AndonDesign uDesign WordPress theme, affecting all releases up to and including 4.11.2. Because the theme fails to verify a user’s privileges before allowing certain operations, an attacker can gain access to actions intended for authenticated or privileged users. This can result in undistributed changes to theme settings, the potential upload of malicious files, or the exposure of sensitive configuration data. The weakness is classified as CWE-862, which indicates that the application is lacking proper authorization controls to separate user capabilities.
Affected Systems
All installations of the AndonDesign uDesign theme on WordPress that are running version 4.11.2 or earlier are susceptible. The issue does not affect newer releases that have applied the vendor’s fix.
Risk and Exploitability
The assessed CVSS score of 5.3 reflects a moderate severity, suggesting that moderate effort and knowledge are required for exploitation. The EPSS score of less than 1 % indicates that, as of this assessment, the likelihood of exploitation is low, and the vulnerability is not listed in CISA’s KEV catalog. The most probable attack vector is the use of crafted HTTP requests targeting theme-protected endpoints that are meant to be accessed only by authenticated users. Successful exploitation would enable an attacker to perform privileged actions such as changing theme options or uploading files, thereby compromising the integrity or security of the site.
OpenCVE Enrichment
EUVD