Impact
The SaasLauncher theme contains a missing authorization flaw that permits the content of a WordPress site to be read or modified through actions that should require higher privileges. Exploitation can result in the unauthorized alteration of data or the addition of malicious content, potentially compromising site integrity and availability. This flaw is classified as CWE‑862, indicating improper access control.
Affected Systems
The affected vendor is CozyThemes, specifically the SaasLauncher WordPress theme. Versions from an unknown baseline through version 1.3.0 are vulnerable. Any WordPress installation running SaasLauncher 1.3.0 or earlier is at risk.
Risk and Exploitability
The CVSS score of 5.0 reflects a moderate severity, and the EPSS score of less than 1% suggests that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the most likely attack vector is through normal web requests to the theme’s administrative endpoints, requiring the ability to supply crafted input. An attacker with access to a WordPress account with administrative or elevated privileges can exploit this flaw to achieve unauthorized access to protected resources.
OpenCVE Enrichment
EUVD