Impact
An incorrect privilege assignment flaw in the Real Estate 7 theme allows an attacker to elevate their privileges within a WordPress site. The vulnerability can enable a user to gain higher permissions than intended, potentially giving them administrative access to modify settings, create or delete content, and access sensitive data.
Affected Systems
The issue affects the contempoinc Real Estate 7 theme for WordPress. All installations from the earliest release through version 3.5.2 are vulnerable; the problem is present in every build up to and including 3.5.2.
Risk and Exploitability
The CVSS score of 7.3 indicates a high severity vulnerability, and the EPSS score of less than 1% suggests a low current exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog. Because the flaw rests in privilege assignment logic, the attack vector is inferred to be through normal user interaction with the WordPress administration interface or a legitimate user account with compromised credentials, rather than a remote code execution vector.
OpenCVE Enrichment
EUVD