Impact
The JNews WordPress theme contains a missing authorization flaw that allows attackers to exploit incorrectly configured access control security levels. This weakness, classified as CWE-862, means that users who normally should have restricted privileges could gain additional access to sensitive theme‑related functionality. By bypassing the intended permissions, an attacker could potentially modify site content, view or edit data that should be protected, or elevate their privileges, compromising the confidentiality and integrity of the site.
Affected Systems
The vulnerability affects the jegtheme JNews WordPress theme, versions from the earliest available build through 11.6.16. Any website using this theme version is susceptible until it is upgraded to a version beyond 11.6.16 where the issue has been corrected.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1% suggests a low exploitation probability at present. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote, through the public web interface of a WordPress site, and would require an attacker to have, or to be able to obtain, a user account with sufficient privileges to trigger the vulnerable functionality. The exploitation requires that the site be running the affected theme version and that the site’s user role configuration has not already been hardened to mitigate this specific access control issue.
OpenCVE Enrichment
EUVD