Impact
The Sober theme released by uixthemes includes an improper authorization flaw that allows an attacker to retrieve sensitive embedded data from the system. This vulnerability stems from the theme’s failure to restrict access to confidential information, leading to a data disclosure issue classified as CWE‑497. The exposure results in loss of confidentiality and potential compromise of sensitive system details. While the defect does not lead to code execution or denial of service, it could allow an unauthorized party to gather valuable data about the underlying WordPress installation.
Affected Systems
WordPress sites utilizing the uixthemes Sober theme versions 3.5.11 and earlier are impacted. Any installation that has not upgraded beyond 3.5.11 remains vulnerable to this data exposure risk.
Risk and Exploitability
With a CVSS score of 5.3 the vulnerability is rated as moderate severity and the EPSS score of less than 1% indicates a very low likelihood of exploitation in the wild. It is not listed in CISA’s KEV catalog. The condition is likely triggered by accessing theme-related resources or rendering pages that reveal the embedded data, and it does not require special privileges or authentication, suggesting a remote, unauthenticated attack vector. The attack vector is inferred because the CVE description does not explicitly state it.
OpenCVE Enrichment