Impact
This vulnerability results from missing authorization checks in the Hogash KALLYAS WordPress theme. An attacker who can target the affected theme may gain unauthorized access to protected resources, potentially modifying content, viewing restricted data, or manipulating site settings. The weakness maps to CWE‑862, reflecting an absence of proper access control verification.
Affected Systems
The problem exists in the hogash KALLYAS theme for WordPress for all releases from the initial release up to and including version 4.22.0. Any site running this theme version is potentially impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity, while the EPSS score of less than 1% shows a very low likelihood of current exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote via the site's public web interface, although the description does not specify the exact access path and therefore this inference may not be deterministic.
OpenCVE Enrichment