Impact
The Lobo theme contains a missing authorization flaw that permits exploitation of incorrectly configured access‑control security levels. An attacker can access or modify privileged theme functions or content that should be restricted, as the vulnerability does not enforce proper authentication or authorization checks.
Affected Systems
All releases of the VanKarWai Lobo theme from its initial public version through 2.8.6 are vulnerable. WordPress sites that are running any of these versions of the theme are at risk.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. The EPSS score of less than 1% suggests a low likelihood of exploitation at present. The issue is not listed in the CISA KEV catalog, so no widespread exploitation has been documented. Attackers would need to target sites where the theme is active and exploit its improperly configured permissions from the front‑end or administrative interfaces.
OpenCVE Enrichment