Impact
The vulnerability is an improper control of code generation exploitation that allows an attacker to inject arbitrary code. It is classified as a code injection flaw (CWE-94) and could enable remote execution of attacker supplied scripts or commands on the affected WordPress installation.
Affected Systems
The4 Molla theme versions up to and including 1.5.13 are affected. Any WordPress site using this theme from its initial release through 1.5.13 is vulnerable, regardless of other plugins or configurations.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, and the EPSS score of less than 1% suggests the probability of exploitation is very low, but it is not absent. The vulnerability is not currently listed in the CISA KEV catalog. Based on the description, the likely attack vector involves an attacker exploiting code injection through the theme’s configuration or upload features, potentially requiring remote interaction with the site.
OpenCVE Enrichment