Impact
The vulnerability is a missing authorization flaw that lets attackers use parts of the Nuss theme that are not properly protected by access control lists. Because these functions are exposed, a malicious user could gain unauthorized access to configuration settings or content that should be restricted, which may lead to data theft or unauthorized changes to the site.
Affected Systems
The issue affects the uxper Nuss WordPress theme versions up to and including 1.3.7.1. Any WordPress installation that has this theme active and is at or below that version is vulnerable.
Risk and Exploitability
The likely attack vector is inferred from the description; the vulnerability description does not explicitly state the attack path, but it is reasonable to assume that an attacker would need to trigger the unprotected theme functions, potentially through a compromised administrative account or by submitting crafted requests to the site. The CVSS score of 7.5 indicates a high severity impact. The EPSS score of less than 1% suggests that exploitation is currently unlikely, and the vulnerability is not listed in CISA KEV. If exploited, the attacker could manipulate sensitive content and potentially pivot to further attacks.
OpenCVE Enrichment
EUVD