Impact
The Electron theme for WordPress contains a Missing Authorization flaw that allows attackers to exploit incorrectly configured access control security levels. This weakness enables unauthorized users to perform actions that should be restricted to privileged accounts, such as creating or modifying content, changing theme settings, or accessing sensitive parts of the site. The vulnerability is identified by CWE-862, which denotes a failure to enforce proper authorization checks, potentially leading to confidentiality, integrity, and availability breaches if the attacker abuses the exposed functionality.
Affected Systems
The affected product is the Ninetheme Electron WordPress theme. Any installation of Electron version 1.8.2 or earlier is vulnerable; no specific patch versions are listed in the description, but the issue applies to all releases up to and including 1.8.2.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate level of severity. The EPSS score of < 1% suggests that, at the time of this analysis, the probability of exploitation is low. The vulnerability is not currently listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote via the web, with an attacker directing crafted HTTP requests to endpoints controlled by the Electron theme. A successful exploitation would grant the attacker privileged control over the theme’s functions, bypassing normal access restrictions.
OpenCVE Enrichment