Impact
The vulnerability arises from a missing authorization check in the Salient WordPress theme, categorized as a Broken Access Control flaw (CWE‑862). An attacker who can exploit this flaw may gain unauthorized access to sensitive theme functionalities or data that should normally be restricted, potentially escalating privileges or performing actions beyond their intended level of access.
Affected Systems
This issue affects the ThemeNectar Salient theme for WordPress, with all releases prior to version 17.4.0 being vulnerable. Users relying on any earlier version should be aware that the theme’s internal access controls are not enforced correctly.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity, while the EPSS probability of less than 1% suggests that, as of now, exploitation is unlikely. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector may involve an authenticated or unauthenticated user exploiting improperly protected theme endpoints; however, explicit details are not provided in the advisory.
OpenCVE Enrichment