Impact
This vulnerability is a missing authorization flaw in the cozythemes HomeLancer theme that lets an attacker exploit incorrectly configured access control security limits. An attacker could gain unauthorized access to restricted areas or perform actions that should be limited to users with proper permissions, compromising the confidentiality and integrity of site data and potentially disrupting normal operations.
Affected Systems
The flaw affects all installations of the HomeLancer theme through version 1.0.1. Users who have not upgraded beyond this version and run the theme on a WordPress site are susceptible. The issue is tied specifically to the cozythemes vendor and its HomeLancer product.
Risk and Exploitability
The assigned CVSS score of 5.4 indicates a moderate severity, while the EPSS score of less than 1% suggests a very low probability of exploitation at this time. The flaw is not listed in the CISA KEV catalog, and no official workaround is provided. Likely attack vectors are remote: an unauthenticated or low‑privilege user could craft requests that bypass the missing authorization checks through exposed theme endpoints or UI elements.
OpenCVE Enrichment