Impact
The Sailing theme contains a missing authorization check that permits attackers to exploit incorrectly configured access control security levels. An attacker could use this flaw to access theme settings, modify configuration values, or perform actions reserved for privileged users. This results in unauthorized exposure of sensitive data or functional compromise. The weakness maps to CWE‑862.
Affected Systems
ThimPress Sailing theme versions earlier than 4.4.6 are vulnerable. All installations using any version prior to the 4.4.6 release are affected.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is through the web interface of the WordPress site, where an unauthenticated or low‑privileged user can send crafted requests to the theme’s admin endpoints.
OpenCVE Enrichment