Impact
A missing authorization flaw in the Anton Shevchuk Constructor theme allows an attacker to invoke functions that should be restricted by access control lists. The vulnerability can lead to unauthorized use of administrative or other sensitive features within a WordPress site. Because the flaw resides in the theme logic, any user who can reach the relevant URLs or interfaces may exploit it.
Affected Systems
The issue affects the Constructor theme for WordPress from any release up to and including version 1.6.5. It is applicable to sites that have this theme installed and active, regardless of the WordPress core version.
Risk and Exploitability
The CVSS base score of 5.3 indicates a moderate risk, and the lack of an EPSS score means there is no publicly reported probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. As the flaw involves missing role checks, the likely attack vector is through the web interface of the affected WordPress installation, potentially via direct URL access or form submission to the theme’s administrative endpoints. The attacker does not need elevated privileges beforehand, enabling any authenticated or even unauthenticated user to gain unauthorized functionality if the theme is exposed.
OpenCVE Enrichment