Impact
The vulnerability is a missing authorization check in Laborator's Kalium WordPress theme that allows an attacker to exploit incorrectly configured access control security levels. It enables unauthorized users to manipulate or access theme settings, potentially leading to content tampering, defacement, or other administrative actions normally reserved for privileged users. The weakness is classified as CWE-862, indicating improper authorization.
Affected Systems
This flaw affects the Laborator Kalium theme for WordPress, versions starting from an unknown earliest release up through 3.18.3 inclusive. Any installation using a vulnerable version is susceptible.
Risk and Exploitability
The CVSS base score of 5.3 reflects moderate severity, while the EPSS score of less than 1% suggests a very low probability of exploitation at the time of analysis. The vulnerability is not listed in CISA’s KEV catalog, indicating no widely known exploitation. Attackers would exploit the issue remotely via the web interface of the theme; the missing authorization check allows them to elevate privileges. Proper authorization controls in a patched version would mitigate this risk.
OpenCVE Enrichment
EUVD