Impact
The AdForest theme for WordPress is vulnerable to an authentication bypass that allows an unauthenticated attacker to log in as any user, including administrators, without a password. The flaw occurs because the theme fails to validate a user’s identity before granting access, enabling full administrative control of the site.
Affected Systems
The vulnerability affects the AdForest WordPress theme sold by scriptsbundle. All releases of the theme up to and including version 6.0.9 are impacted. Sites that have not upgraded beyond 6.0.9 are at risk.
Risk and Exploitability
The CVSS score of 9.8 marks the flaw as critical and indicates a complete takeover of the site if exploited. The EPSS score of less than 1% suggests that exploitation is currently unlikely, but the high severity remains. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that attackers can exploit the flaw by sending an unauthenticated request to the theme’s authentication process; no special access or credentials are required.
OpenCVE Enrichment