Impact
The vulnerability is a missing authorization flaw in the 8theme XStore WordPress theme. Incorrectly configured access control security levels allow an attacker to reach privileged theme management interfaces that should be restricted, enabling unauthorized changes to theme configuration and other site settings.
Affected Systems
All installations of the 8theme XStore theme from its earliest release up to, but not including, version 9.6 are affected. The issue is present on WordPress sites that have the theme activated; other versions of the theme are not impacted.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity, while the EPSS score of less than 1% suggests a very low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote via the web interface, as the flaw allows resolution of incorrectly enforced access control. This assessment is inferred from the description of missing authorization; the description does not explicitly state the precise exploit method.
OpenCVE Enrichment