Impact
The vulnerability is a missing authorization flaw that allows unauthorized users to perform actions that should be restricted to privileged roles. This defect is classified as CWE‑862 and can lead to unauthorized modification or access to sensitive data managed by the theme. Because the flaw resides in the Listihub theme code, any user who can interact with the theme’s interfaces may exploit the weakness, resulting in data disclosure or unauthorized configuration changes.
Affected Systems
Affected products are the e‑plugins Listihub theme for WordPress, any installation running version 1.0.6 or earlier. No specific sub‑versions are enumerated, and the issue applies to all releases from the initial version up to the stated limit.
Risk and Exploitability
The CVSS score of 7.3 indicates a high severity risk, while the EPSS score of less than 1% suggests a low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Based on the description the likely attack vector involves authenticated or unauthenticated users interacting with the theme’s front‑end or admin pages; attackers may exploit the broken access control to elevate privileges or gain unauthorized access to theme data.
OpenCVE Enrichment