Impact
Desertthemes SoftMe includes a missing authorization check that permits users to exploit incorrectly configured access control security levels. The flaw allows a user who should be restricted from accessing certain features or data to do so, thereby granting elevated privileges. This leads to potential disclosure of private site content or configuration settings and may enable further actions within the WordPress environment.
Affected Systems
WordPress sites that have installed the SoftMe theme version 1.1.27 or earlier. The vulnerability applies to all releases from the initial release (n/a) through 1.1.27 inclusive.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate impact, with an EPSS score of less than 1% suggesting a low probability of real‑world exploitation at the present time. The vulnerability is not listed in the CISA KEV catalog. The likely attack path involves a user interacting with or manipulating URLs or API endpoints that are protected by the theme’s access control. An attacker may use this vector to bypass intended restrictions, though the exploitation would require either provided access credentials or an existing vulnerability that allows authenticated interaction. Given the moderate severity and low exploitation likelihood, the risk remains manageable but warrants assessment on a case‑by‑case basis.
OpenCVE Enrichment
EUVD