Impact
The vulnerability is a missing authorization check that permits an unauthenticated user to perform privileged operations within the WordPress site. By bypassing the required access controls, an attacker could read, modify, or delete content and configuration, leading to violations of confidentiality, integrity, and potentially availability. The weakness is identified as CWE-862 – Missing Authorization.
Affected Systems
All installations of the WordPress Togo theme provided by uxper that use a version earlier than 1.0.4 are vulnerable. The affected range is n/a through < 1.0.4, meaning any current or legacy deployment of the theme prior to the 1.0.4 release is susceptible.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers could potentially exploit the flaw remotely by interacting with the WordPress web interface, especially through administrative or editor endpoints lacking proper permission checks.
OpenCVE Enrichment