Impact
This vulnerability is a missing authorization flaw in the ThemeRain Core WordPress plugin, allowing an attacker to bypass normal access controls and perform actions that should be restricted to privileged users. The flaw is categorized as CWE-862 and could let an attacker gain unauthorized access to sensitive functionalities within the plugin, potentially exposing or modifying site content or configuration.
Affected Systems
The affected product is the ThemeRain Core plugin from the Themerain vendor. All versions up to 1.1.9 are impacted, including any earlier releases whose versioning is unspecified. Users running these plugin versions should be aware that the security boundary between regular users and administrators is compromised.
Risk and Exploitability
The CVSS score of 5.3 places this vulnerability in the moderate severity range. The EPSS score of less than 1 percent implies that it is not widely exploited in the wild. The vulnerability is not listed in the CISA KEV catalog, indicating a lower priority for immediate exploitation. Based on the description, the likely attack vector is that any authenticated user who can access the plugin’s administrative pages can exploit the missing checks, possibly by sending crafted requests to endpoints that lack proper role validation.
OpenCVE Enrichment