Impact
The WoodMart theme contains an information exposure flaw in the woodmart_get_posts_by_query() function; the function fails to enforce proper access checks, allowing an unauthenticated user to retrieve the content of password‑protected, private, or draft posts. This is a CWE‑200 weakness that can leak sensitive post data.
Affected Systems
This vulnerability affects the xTemos WoodMart WordPress theme, versions 8.2.5 and earlier. Any website running those versions is potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, while the EPSS score of less than 1% signals that exploitation is unlikely at present, and it is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker can provoke the flaw by sending a standard HTTP request to the theme’s front‑end endpoints and receive unrestricted post data, meaning the attack is feasible over the network from any host.
OpenCVE Enrichment
EUVD