Impact
A missing capability check in the clean() function of the Constructor WordPress theme permits authenticated users with Subscriber-level access or higher to trigger a theme clean operation. This operation can remove or reset theme files and potentially alter or delete site content, thereby compromising the integrity of the website.
Affected Systems
The vulnerability affects all installations of the Constructor theme from the vendor "antonshevchuk:Constructor" for versions up to and including 1.6.5.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, while the EPSS score of less than 1% shows a very low probability of exploitation currently. The issue is not listed in CISA’s KEV catalog. Attackers must be authenticated with Subscriber or higher privileges to exploit the flaw, making the risk contingent on the presence of such accounts.
OpenCVE Enrichment
EUVD