Impact
This vulnerability is a missing authorization flaw in the Shk Corporate WordPress theme. It allows exploitation of incorrectly configured access control settings, which may enable unauthorized access to administrative functions or content within the theme. While the flaw does not enable remote code execution, it can result in data disclosure or unauthorized content modification. The weakness is categorized as CWE-862.
Affected Systems
The issue affects the Shk Corporate theme developed by priyanshumittal. All releases from the earliest available version up through version 2.4.1.1 are vulnerable. Hosts running any of these theme versions on a WordPress installation are at risk.
Risk and Exploitability
The CVSS score of 4.3 denotes a low severity overall, and the EPSS probability of less than 1% suggests a very low likelihood of exploitation in the wild. Because the flaw relies on incorrect access control configuration, the CVE description does not explicitly state the required attacker capabilities; it can be inferred that the attacker would need at least some level of authenticated access or the ability to manipulate the WordPress role hierarchy. The vulnerability is not listed in the CISA KEV catalog, indicating no widespread or confirmed exploitation at the time of reporting.
OpenCVE Enrichment
EUVD