Impact
This vulnerability is a missing authorization flaw that permits an attacker to exploit incorrectly configured access control security levels. The weakness allows unauthorized users to access functionality that should be restricted to privileged accounts, potentially resulting in unauthorized data disclosure or modification. It is classified as CWE-862, which indicates session or user authentication failures.
Affected Systems
The issue affects the G5Theme Zorka WordPress theme in all versions through 1.5.7. WordPress sites that have the Zorka theme installed and do not upgrade past this version are vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1% reflects a very low probability of exploitation as of now. The vulnerability is not listed in the CISA KEV catalog. Based on the nature of the flaw and the fact that it is a web‑based plugin, the likely attack vector is remote, where an attacker can issue HTTP requests to URLs that are incorrectly protected by the theme’s access controls. No additional prerequisites are stated in the description, so any user who can reach the affected theme’s endpoints could potentially exploit the flaw.
OpenCVE Enrichment