Impact
The vulnerability is a missing authorization check in Mikado‑Themes’ Wanderland theme, allowing an attacker to exploit incorrectly configured access‑control security levels. The flaw can enable unrestricted access to theme administrative functions, potentially permitting unauthorized viewing, modification, or deletion of site content and configuration.
Affected Systems
The affected product is the Mikado‑Themes Wanderland WordPress theme. Versions from the initial release up through 1.5 are vulnerable; any installation of the theme in those versions is impacted.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Exploitation likely requires HTTP requests to the WordPress site, where an attacker can manipulate requests to bypass normal permission checks; the attack vector is inferred rather than explicitly documented in the provided data.
OpenCVE Enrichment