Impact
The Arcane theme for WordPress contains a missing authorization flaw that allows an attacker to bypass required access checks. This broken access control can enable a non‑privileged user to access restricted areas of a WordPress site, potentially reading, editing, or deleting content that should be protected. The weakness is identified as an authorization failure (CWE-862).
Affected Systems
The vulnerability affects Skywarrior Arcane theme versions from the earliest available release up to and including 3.6.6. Any WordPress installation running this theme within that version range is susceptible.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation at the present time, and the issue is not listed in the CISA KEV catalog. The likely attack vector is remote via the website; an attacker can obtain the vulnerability by accessing the site over the network, possibly without authentication, and manipulating requests to trigger the broken authorization logic. Exploiting the weakness would not provide system‑wide compromise but could expose or alter site data, undermining confidentiality, integrity, and availability of the affected WordPress site.
OpenCVE Enrichment