Impact
The vulnerability is a missing authorization flaw that allows an attacker to bypass incorrectly configured access controls, potentially enabling unauthorized viewing or manipulation of content protected by the Modernize theme.
Affected Systems
GoodLayers Modernize theme versions through 3.4.0 inclusive are affected.
Risk and Exploitability
The CVSS score of 4.3 indicates a low severity impact, and the EPSS score of less than 1% shows a very low probability of exploitation. The vulnerability is not listed in CISA KEV. Based on the description, the likely attack vector is via the web interface of a WordPress site running an affected version of the Modernize theme, where an attacker could access restricted content or modify protected data if access controls are misconfigured.
OpenCVE Enrichment
EUVD