Impact
The vulnerability is a missing authorization flaw in the Solace WordPress theme, where incorrectly configured access control security levels allow unauthorized users to perform actions that should be restricted. This flaw could enable a non-privileged user to access administrative functions or modify content if the theme’s internal checks are bypassed. The impact is limited to confidentiality or integrity of site data through unauthorized access to restricted resources, and it is categorized under CWE-862.
Affected Systems
WordPress sites that use the Solace theme version 2.1.16 or earlier are affected. The vulnerability targets the Solace theme package distributed by the vendor solacewp; any WordPress installation that has not updated beyond version 2.1.16 is at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity risk. The EPSS score of less than 1% suggests a low probability of exploitation at this time. This vulnerability is not listed in the CISA KEV catalog, which reduces its priority relative to known exploited vulnerabilities. The likely attack vector is the web application layer; an attacker can send crafted HTTP requests to the theme’s exposed endpoints without needing prior authentication. A successful exploit would grant the attacker unauthorized access to protected theme functions or data.
OpenCVE Enrichment