Description
Missing Authorization vulnerability in SmartDataSoft DriCub dricub-driving-school allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DriCub: from n/a through <= 2.9.
Published: 2025-09-22
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing authorization flaw allows the exploitation of incorrectly configured access control security levels in the SmartDataSoft DriCub WordPress theme. The vulnerability amounts to a CWE-862 weakness: an attacker could perform actions or view resources that should be restricted to authorized users. The impact is the potential unauthorized disclosure or manipulation of protected data within the site, which can undermine confidentiality and integrity for the affected content.

Affected Systems

SmartDataSoft DriCub WordPress Theme versions up to and including 2.9 are vulnerable. Any WordPress site installing these versions of the theme is impacted.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity, and the EPSS score of less than 1% suggests that the likelihood of exploitation is currently very low. The vulnerability is not listed in the CISA KEV catalog, further indicating limited recent exploitation. Because the flaw involves broken access control rather than a remote code execution vector, the attacker would need to interact with the site—likely the front‑end or an authenticated user session—to succeed. Based on the description, the likely attack vector is an interaction with the site’s front‑end or an authenticated session, targeting an endpoint exposed by the theme that lacks proper authorization checks. The exact entry point is not specified, but an attacker could target any accessible page or API endpoint that the theme provides and that is improperly protected.

Generated by OpenCVE AI on April 30, 2026 at 06:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update SmartDataSoft DriCub to a version newer than 2.9 when available.
  • If no upgrade is immediately possible, deactivate or uninstall the DriCub theme to eliminate the vulnerability.
  • As a temporary measure or for additional protection, enforce strict role‑based access control in the WordPress installation, ensuring that any theme‑provided functions are wrapped with proper capability checks (e.g., using current_user_can).
  • Optionally, monitor the site for unusual access patterns that could indicate exploitation attempts.

Generated by OpenCVE AI on April 30, 2026 at 06:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-30624 Missing Authorization vulnerability in SmartDataSoft DriCub allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects DriCub: from n/a through 2.9.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in SmartDataSoft DriCub allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects DriCub: from n/a through 2.9. Missing Authorization vulnerability in SmartDataSoft DriCub dricub-driving-school allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects DriCub: from n/a through <= 2.9.
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Tue, 23 Sep 2025 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Tue, 23 Sep 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 22 Sep 2025 18:30:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in SmartDataSoft DriCub allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects DriCub: from n/a through 2.9.
Title WordPress DriCub Theme <= 2.9 - Broken Access Control Vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:40.351Z

Reserved: 2025-08-22T11:37:41.965Z

Link: CVE-2025-58004

cve-icon Vulnrichment

Updated: 2025-09-23T14:38:02.660Z

cve-icon NVD

Status : Deferred

Published: 2025-09-22T19:16:01.690

Modified: 2026-04-23T15:33:13.130

Link: CVE-2025-58004

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T06:45:16Z

Weaknesses