Impact
The vulnerability is a missing authorization check in the Blocksy theme, which can allow users without proper privileges to perform actions reserved for higher-level roles. It is inferred that an attacker with any account could access or modify theme settings and potentially inject content or alter site appearance. This is a classic broken access control flaw, classified as CWE‑862.
Affected Systems
WordPress installations that use the Blocksy theme up to and including version 2.0.97 are vulnerable. The vulnerability applies to all versions from an unspecified starting point through 2.0.97. Versions newer than 2.0.97 are not affected.
Risk and Exploitability
The CVSS score of 4.9 denotes moderate severity, and the EPSS score of less than 1 % indicates a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack path involves an authenticated user accessing the theme’s configuration interface and exploiting the missing authorization check to elevate privileges; this is inferred from the description.
OpenCVE Enrichment
EUVD