Impact
A vulnerability in Elated-Themes Search & Go allows attackers to exploit the password recovery process by bypassing normal authentication. By leveraging an alternate path or channel, an attacker can trigger the password reset mechanism and set a new password, effectively gaining unauthorized access to user accounts. The potential impact includes full account takeover, data exfiltration, and further site compromise.
Affected Systems
The issue affects WordPress sites using the Elated-Themes Search & Go theme through version 2.7, inclusive of all prior releases. Any site that has not upgraded beyond 2.7 is vulnerable.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity, yet the EPSS score is less than 1%, suggesting a low probability of current exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is the web-based password recovery endpoint, which an attacker can \n\naccess remotely without prior authentication. While this path is not a privileged attack, it still grants full access to compromised accounts.
OpenCVE Enrichment