Impact
The Stratus theme suffers a missing authorization flaw in Pixel Makers Creative INC’s WordPress theme. Incorrectly configured access‑control rules let an attacker exploit the theme’s administrative functions, enabling unauthorized access to privileged operations. The flaw is classified as CWE‑862, indicating that users with lower privileges can perform actions reserved for higher‑privileged accounts.
Affected Systems
The Stratus theme (versions prior to 4.2.11) from Pixel Makers Creative INC is affected. No further version details are specified in the CVE data.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation. The flaw is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attacker could send crafted HTTP requests to restricted administrative endpoints of the theme, as the issue stems from incorrectly configured access control security levels. Having local or web-based access to the site could allow an attacker to exploit the missing authorization and elevate privileges.
OpenCVE Enrichment
EUVD