Impact
The vulnerability originates from incorrect privilege assignment logic in the RealHomes WordPress theme, allowing an attacker to gain higher-level access than intended. This flaw enables a user to elevate their privileges within the WordPress installation, potentially granting administrative capabilities. The weakness maps to CWE-266, which highlights improper privilege management.
Affected Systems
The vulnerability affects the InspiryThemes RealHomes theme for WordPress in all versions from the earliest available release up to and including version 4.4.0. Administrators using any of these versions should verify the exact theme version in use.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity, whereas the EPSS score of less than 1% suggests that the likelihood of exploitation is currently very low. The issue is not listed in the CISA KEV catalog, implying no confirmed active exploit in the wild. The likely attack vector would involve leveraging authenticated user actions within the theme, but the specific execution path is not detailed in the description and must be inferred. Overall, the risk combines high impact with low current exploit probability, but the critical nature of privilege escalation warrants proactive remediation.
OpenCVE Enrichment
EUVD