Impact
Missing authorization in Themovation Bellevue theme allows unauthenticated or low‑privileged users to access booking management functions that should be restricted. The breach can let an attacker view, modify, or delete booking records, undermining data confidentiality, integrity, and potentially leading to financial loss or reputational damage. The flaw is classified as CWE‑862 – Broken Access Control.
Affected Systems
Vulnerable versions of the Bellevue WordPress theme from Themovation, specifically every release up to and including 4.2.2, are affected. No other products or vendors are listed. The vulnerability applies regardless of the WordPress installation version but only when the offending theme is active.
Risk and Exploitability
The CVSS score of 4.3 suggests a moderate severity, and the EPSS score of less than 1% indicates a low likelihood of exploitation in the wild. It is not currently listed in the CISA KEV catalog. The attack vector is inferred to be through the web application, taking advantage of the theme’s booking‑management endpoints that do not perform proper authorization checks. An attacker with access to the site’s front‑end or an existing authenticated user with limited rights could elevate privileges to perform unauthorized actions.
OpenCVE Enrichment
EUVD