Impact
The kamleshyadav Medicalequipment WordPress theme is affected by a missing authorization check that allows attackers to bypass normal access restrictions. This Missing Authorization flaw (CWE‑862) can enable attackers to perform actions normally reserved for authenticated users, such as creating, editing, or deleting content, or viewing restricted information. The publicly disclosed CVSS score of 5.3 indicates a moderate severity impact.
Affected Systems
Any installation of the kamleshyadav Medicalequipment WordPress theme version 1.0.9 or earlier is vulnerable. The issue applies to all configurations where the theme is active and at or below the listed version.
Risk and Exploitability
The EPSS score of less than 1% suggests a low probability of real‑world exploitation, and the weakness is not listed in CISA’s KEV catalog. The likely attack vector is remote, via crafted Web requests to functionality provided by the vulnerable theme, allowing an unauthenticated or unauthorized user to perform privileged actions. Overall the risk is moderate, with potential for significant data modification or disclosure on affected sites.
OpenCVE Enrichment