Impact
Missing authorization in the Jthemes Exzo theme lets an attacker bypass access control checks and modify or view protected resources, potentially exposing or altering sensitive information. This is a broken access control flaw (CWE‑862) that could enable unauthorized changes to theme settings or file edits.
Affected Systems
Exzo theme (Jthemes) version 1.2.4 and earlier on WordPress installations are affected. Any site using this theme under the specified version range is vulnerable.
Risk and Exploitability
CVSS score of 7.5 indicates high severity, while an EPSS score of less than 1% suggests low current exploitation probability. The flaw has not been listed in CISA's KEV catalog. Exploitation appears to target the theme's file editing and settings interfaces; it likely requires authenticated access to the WordPress admin area but may be tricked into bypassing restrictions. In practice, the attack vector is inferred to be a web‑based exploitation through the WordPress dashboard, but the description does not specify external triggering.
OpenCVE Enrichment