Impact
The vulnerability is a missing authorization flaw in the WordPress PenNews theme, allowing attackers to exploit incorrectly configured access control security levels. It permits unauthorized users to gain privileged access to areas of the site that should be restricted, potentially enabling the viewing or modification of sensitive content.
Affected Systems
Affecting the PenNews theme developed by PenciDesign, all versions below 6.7.4 are vulnerable. The issue applies to installations of the theme within WordPress sites that have not been upgraded past version 6.7.4.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of <1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is through ordinary web requests to a site using the vulnerable theme, and an attacker could misuse the broken access controls to access or modify protected content without proper authorization.
OpenCVE Enrichment