Impact
The EscortWP WordPress theme through version 3.6.2 contains a vendor‑authored, obfuscated backdoor that allows any unauthenticated user who supplies a hard‑coded, per‑build key to permanently delete all content on a site and to silently transmit the site URL, administrator e‑mail address, and license key to a third‑party server. This flaw represents a breach of access control and results in information exposure; it is inferred that the weakness aligns with CWE‑284 (Improper Access Control) and CWE‑200 (Information Exposure).
Affected Systems
Any WordPress site that installs the EscortWP theme version 3.6.2 or older—identified in the CVE as Unknown:escortwp—is affected; no other vendors or products are listed.
Risk and Exploitability
The CVSS score of 7.5 highlights the high impact on confidentiality, integrity, and availability, while the EPSS score of < 1% indicates a very low but non‑zero probability of exploitation. The vulnerability can be triggered by an unauthenticated HTTP request containing the obsolete key, enabling the attacker to carry out the deletion and exfiltration without bypassing normal authentication. No public exploit listings appear in the CISA KEV catalog, but the guaranteed ability to erase all site content and leak sensitive data results in a high risk for sites that lack rapid recovery or backup procedures.
OpenCVE Enrichment