Impact
The vulnerability is a missing authorization flaw that enables users to perform actions they should not have permission for. An attacker who can authenticate to the WordPress site can exploit incorrect access‑control levels within the wpresidence theme and gain the ability to create, edit, or delete theme‑related content, effectively compromising the site’s integrity.
Affected Systems
This flaw affects installations of the WpEstate wpresidence WordPress theme released up to and including version 5.3.2. Any WordPress site running a version in this range with the wpresidence theme installed is potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity in the absence of other factors. The EPSS score of less than 1% shows a very low current exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be remote, requiring an authenticated user to access the vulnerable theme functionality; once authenticated, the attacker can perform unauthorized administrative actions on the site.
OpenCVE Enrichment