Impact
The Hello FSE Blog theme has a missing authorization flaw that permits the execution of protected functions without proper access checks. This condition can allow an attacker to perform actions normally restricted to higher‑privilege users, potentially compromising the integrity of site content. The weakness is identified as CWE-862, which denotes unauthorized access or privilege escalation.
Affected Systems
WordPress sites that use the sparklewpthemes Hello FSE Blog theme version 1.0.6 or earlier are affected. No other WordPress themes or products are listed as impacted by this vulnerability.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate impact for a typical exploitation scenario, and the EPSS score of less than 1% signals a low probability of being actively exploited in the wild. The vulnerability is not included in the CISA KEV catalog. The likely attack vector, inferred from the description of lacking authorization checks, involves interacting with theme‑level functionality through administrative or public pages that do not enforce proper capability checks, although no public exploit examples are documented.
OpenCVE Enrichment
EUVD