Impact
The vulnerability is a missing authorization flaw that enables attackers to gain unauthorized access to privileged operations within the WordPress Stratus theme. Identified as CWE‑862, this flaw permits actions that should only be available to users with higher privilege levels.
Affected Systems
The Stratus theme (version 4.2.5 and earlier) from Themovation App, SaaS & Software Startup Tech Theme – Stratus are affected. No further version details are specified in the CVE data.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation. The flaw is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker could send crafted HTTP requests to restricted administrative endpoints of the theme, as the issue stems from incorrectly configured access control security levels. Having local or web-based access to the site could allow an attacker to exploit the missing authorization and elevate privileges.
OpenCVE Enrichment
EUVD