Impact
This vulnerability is an Authorization Bypass Through User-Controlled Key (CWE-639) in the Mikado-Themes Justicia WordPress theme, available up to version 1.2. It permits an attacker to exploit incorrectly configured access control security levels to read or modify restricted content or data. The primary impact is the compromise of confidentiality and integrity of site data, potentially enabling privilege escalation.
Affected Systems
The affected product is the Mikado-Themes Justicia WordPress theme, versions from the earliest release through 1.2. Any WordPress installation that uses this theme may be at risk.
Risk and Exploitability
The CVSS v3.1 base score of 5.4 indicates moderate severity, with a low exploit probability of less than 1% per the EPSS metric and no listing in the CISA KEV catalog. The likely attack vector is a web-based request manipulation of user-controlled keys, allowing attackers to access restricted objects without proper authorization checks.
OpenCVE Enrichment