Impact
This vulnerability is a missing authorization flaw (CWE-862) that allows attackers to read protected data beyond their intended access rights. By exploiting incorrectly configured access control security levels within the MediCenter theme, an attacker can obtain sensitive information normally restricted. The issue does not provide for arbitrary code execution, but it makes confidential data publicly available to unauthorized users.
Affected Systems
The weakness affects the QuanticaLabs MediCenter – Health Medical Clinic WordPress theme. All releases prior to 14.7 are affected, including the current version that the vulnerability entry lists as "n/a through < 14.7."
Risk and Exploitability
The CVSS score of 5.3 indicates moderate possible impact, and the EPSS score of < 1% suggests exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote via web requests where an unauthenticated or improperly authenticated user can access protected resources by manipulating URLs or inputs to the theme’s hidden endpoints.
OpenCVE Enrichment
EUVD