Impact
The vulnerability in the Fleur theme permits an attacker to use crafted URLs or parameters to access content or files that belong to other users or site sections, bypassing the intended authorization controls. The primary impact is the exposure of confidential data or modification of protected resources, classified as an IDOR flaw (CWE‑639).
Affected Systems
Affected are installations of the Mikado‑Themes Fleur theme up to and including version 2.0. Any WordPress site deploying this theme, regardless of installed roles, is potentially vulnerable.
Risk and Exploitability
Based on the description, the likely attack vector is via HTTP requests that reference non‑owned object identifiers; no elevated privileges or authentication are required beyond a legitimate visitor. The moderate CVSS score (5.4) combined with a very low EPSS (<1%) and absence from KEV suggest a limited exploitation probability, though the flaw still allows direct privilege escalation if discovered and exploited.
OpenCVE Enrichment