Impact
A missing authorization flaw in Jthemes xSmart allows attackers to exploit incorrectly configured access control security levels. The flaw permits users to perform actions beyond their permitted roles, potentially modifying or accessing content they should not see. It is a classic example of missing function level permissions identified as CWE-862.
Affected Systems
Jthemes xSmart theme versions up to and including 1.2.9.4 are affected. All earlier releases are also in scope because the vulnerability exists from the earliest available version through this maximum version.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, while the EPSS score of less than 1% shows that exploitation is currently unlikely but not impossible. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is via the WordPress admin interface or a publicly exposed page that leverages an authenticated user session. An attacker would need to log in as any WordPress user and then use the theme’s functionality to bypass proper role checks, leading to unauthorized data modification or disclosure.
OpenCVE Enrichment