Impact
An incorrect privilege assignment flaw exists in the Jthemes Sale! Immigration law, Visa services support, Migration Agent Consulting WordPress theme, which allows an attacker to elevate privileges. The weakness is classified as CWE-266 and can lead to unauthorized higher level access to the site, enabling further compromise or damage.
Affected Systems
The vulnerability affects the WordPress theme named Sale! Immigration law, Visa services support, Migration Agent Consulting (immiex) from its initial release up to and including version 1.5.8. No other vendors or products are listed as affected.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity risk, while the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that a user with a limited role can trigger the theme’s code to gain higher privileges through the web interface, potentially allowing full site compromise.
OpenCVE Enrichment