Impact
Missing authorization in HaruTheme Frames allows attackers to access restricted areas or perform actions they should not be permitted to. The flaw stems from incorrectly configured access control security levels, which is a classic Broken Access Control weakness (CWE-862). Attackers could read, modify, or delete content, potentially compromising the confidentiality and integrity of site data, and could also impersonate privileged users.
Affected Systems
All installations of the HaruTheme Frames WordPress theme up to and including version 1.5.7 are vulnerable. The flaw is present in every build before 1.5.8, and no specific sub‑versions have been identified as safe. Site owners should verify the theme version and consider the upgrade path.
Risk and Exploitability
The CVSS base score of 4.3 reflects a moderate impact, and the very low EPSS score (<1%) suggests that exploitation is unlikely at this time. The vulnerability is not listed in CISA’s KEV catalog, indicating no known active exploitation. However, because the flaw permits unauthorized access, it could serve as a stepping stone for other attacks if an attacker is able to reach the site’s admin interface. Based on the description, the likely attack vector is remote over the network, and no local privilege escalation is required.
OpenCVE Enrichment
EUVD