Impact
Affected versions of the Altair theme for WordPress allow an attacker to perform actions that normally require authentication because the theme fails to enforce proper access control on privileged operations. The vulnerability falls under CWE‑862, indicating that authorization checks are missing or insufficient. If exploited, an unauthenticated user could perform functions that should be limited to site administrators, potentially modifying site content or configurations.
Affected Systems
ThemeGoods Altair theme versions up to and including 5.2.2 are susceptible to this flaw. The vulnerability affects any WordPress installation that has the Altair theme activated and uses one of the mentioned versions. No specific WordPress core versions are listed as affected, but the theme exists on all common WordPress setups where it is installed.
Risk and Exploitability
The CVSS base score of 6.5 marks this as a medium severity issue, and the EPSS score is not available, so the likelihood of exploitation cannot be quantified from the data provided. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is through web requests to theme‑related endpoints that do not perform authentication checks, enabling an attacker to carry out privileged actions without credentials. Such exploitation would compromise the integrity of site content and could serve as a foothold for further attacks.
OpenCVE Enrichment