Impact
This vulnerability is a missing authorization flaw in the pressmaximum Customify WordPress theme that allows an attacker to exploit incorrectly configured access control security levels. The weakness, classified as CWE‑862, can enable an unauthorized user to access or manipulate privileged functions within the theme, potentially leading to unauthorized data disclosure, modification, or other security impacts. The CVSS score of 5.4 indicates a moderate severity level.
Affected Systems
WordPress installations that use the pressmaximum Customify theme version 0.4.8 or earlier are affected.
Risk and Exploitability
The exposure is moderate, with an EPSS score of less than 1 % and no listing in the CISA KEV catalog. Exploitation appears to be achievable through the theme’s administrative interfaces or other exposed parts of the WordPress site that rely on the Customify theme’s access controls. An attacker who can interact with these interfaces could gain unauthorized actions or data access without needing administrative credentials, though the exact attack path is not fully detailed in the official description.
OpenCVE Enrichment
EUVD