Impact
Missing authorization in the HotStar – Multi‑Purpose Business Theme allows attackers to bypass configured access control restrictions, enabling unauthorized use of administrative functions within a WordPress site. The weakness is classified as CWE‑862 (Missing Authorization). The potential impact is the ability to perform actions that should be restricted to privileged users, compromising confidentiality, integrity, or availability of site data and functionality.
Affected Systems
The vulnerability affects the themeton HotStar – Multi‑Purpose Business Theme for WordPress version 1.4 and earlier. Any site running these theme versions is susceptible, regardless of the WordPress core version.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score is less than 1 percent, implying a low probability of exploitation at the time of assessment, and the vulnerability is not listed in CISA's KEV catalog. The likely attack vector is via web requests that target theme configuration or administrative endpoints; attackers could exploit the missing authentication checks if they can access a user session or craft crafted requests. Because the flaw is in the theme’s access control logic, attackers would need to identify the vulnerable functions, which are exposed through the WordPress admin interface or theme‑specific endpoints.
OpenCVE Enrichment
EUVD