Impact
The vulnerability in the NordicMade Savoy WordPress theme up through version 3.0.8 allows an unauthenticated or unauthorized user to retrieve sensitive system information. Because the theme fails to enforce proper authorization checks, a malicious actor can extract embedded data that may include configuration, environment, or user details. This data exposure can aid further attacks such as credential theft or targeted exploitation, and is catalogued as CWE‑497, indicating improper authorization over sensitive information.
Affected Systems
WordPress sites that deploy the Savoy theme by NordicMade and use version 3.0.8 or earlier are affected. All custom WordPress installations that have not upgraded beyond this version are vulnerable; no other themes or core WordPress components are impacted.
Risk and Exploitability
The CVSS score of 5.3 signals medium severity, while the EPSS score of less than 1% indicates a low likelihood of exploitation. The vulnerability is not yet in CISA’s KEV catalog. The patch notes do not specify an attack vector, so it is inferred that an attacker would trigger the vulnerable functionality through a web request, possibly as an unauthenticated user, to access the exposed data. The lack of authorization checks enables this remote data retrieval.
OpenCVE Enrichment
EUVD