Impact
Elated-Themes The Aisle theme contains a missing authorization flaw that allows exploitation of incorrectly configured access control security levels. The vulnerability is identified as CWE-862, which signifies that legitimate users may be granted privileges they should not have, potentially enabling malicious actors to view or alter protected settings within the theme. By exploiting this weakness, an attacker could gain unauthorized control over theme configuration, modify visual elements or inject custom code that could be used to compromise the broader WordPress installation.
Affected Systems
The vulnerability impacts the Elated-Themes The Aisle WordPress theme, affecting all installed versions from the unspecified earliest release through version 2.9. Any site running this theme up to and including that version is at risk.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity, while the EPSS score of less than 1% suggests that exploitation is likely rare and not actively targeted. The vulnerability is not listed in the CISA KEV catalog. Attacks would likely occur via the web interface where the theme’s settings are exposed: a remote actor with legitimate or stolen credentials could navigate to the theme options and gain elevated privileges that bypass the expected authorization checks.
OpenCVE Enrichment