Impact
The vulnerability is a missing authorization flaw that allows attackers to bypass incorrectly configured access control settings within the Theme. By exploiting this issue, an attacker can gain unauthorized access to privileged functions or content that should be restricted, potentially modifying or viewing sensitive data on the site.
Affected Systems
The defect affects the WordPress Construction Light theme from the entry level up through version 1.6.7. Any WordPress installation that has this theme applied is at risk until the theme is updated beyond version 1.6.7.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate risk level, while the EPSS score of less than 1% suggests that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog, further indicating limited public exploitation. The attack vector is inferred to be via standard web requests to the theme’s privileged endpoints; an attacker could send crafted HTTP requests to access protected resources without proper authentication.
OpenCVE Enrichment