Impact
The WordPress imEvent theme contains a missing authorization check that allows unauthorized users to invoke protected functionality. This flaw is identified as CWE‑862, a broken access control weakness. Attackers who exploit this can potentially read, modify, or delete data or perform administrative actions that should be restricted, leading to confidentiality or integrity violations of the site and its content.
Affected Systems
The vulnerability affects the Jthemes imEvent product, all versions from its initial release up through version 3.4.0. Clients using any older release of the theme are at risk until an updated theme is applied.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves sending specially crafted HTTP requests to WordPress endpoints that expose the theme’s functions; this would be carried out over the network by an attacker who can reach the site. In the absence of a properly configured ACL, the flaw permits privileged actions to be performed by unauthenticated actors.
OpenCVE Enrichment