Impact
The Hestia theme contains a missing authorization check that allows users to trigger actions that should only be available to privileged users. This results in a broken access control vulnerability that could let an attacker exploit extra functionality or modify site settings. The weakness corresponds to CWE‑862.
Affected Systems
The vulnerability affects the Hestia theme provided by themeisle, specifically all releases up to and including version 3.2.10.
Risk and Exploitability
The CVSS score of 5.3 categorizes the flaw as moderate risk. The EPSS score of less than 1 % indicates a very low probability that the vulnerability will be actively exploited. The vulnerability is not listed in the CISA KEV catalog. Based on the description it is likely that an attacker can exploit the flaw by accessing unsecured theme endpoints via a web browser, perhaps as any authenticated user, or possibly even by an unauthenticated visitor if the endpoint is publicly exposed. No other exploitation prerequisites are mentioned.
OpenCVE Enrichment
EUVD