Impact
The VW Writer Blog theme for WordPress allows an authenticated user with Subscriber-level access and above to execute the vw_writer_blog_reset_all_settings function without a capability check. This results in the entire set of theme customizer options being restored to default values. As a consequence the site owner loses all theme configuration—such as colors, layouts, and site branding—which may disrupt the site’s appearance and functionality. No code execution or data exfiltration is possible, but the loss of configuration can be significant for site operators.
Affected Systems
Any installation of the VW Writer Blog theme version 1.3.8 or earlier on a WordPress site. The vulnerability is present in all versions up to 1.3.8 and does not apply to 1.3.9 or later. The affected vendor is vowelweb.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate risk, but the EPSS score of less than 1% shows the likelihood of exploitation is very low. The vulnerability is not listed in CISA KEV. Because the flaw requires an authenticated user owning at least a Subscriber role, an attacker must first compromise WordPress credentials or elevate a legitimate user to a higher role. After gaining those privileges, the attacker can reset all theme settings. The lack of an immediate destructive outcome reduces urgency, yet the loss of configuration can lead to significant operational impact. The typical attack vector is through the WordPress admin interface by submitting a request that triggers the reset function.
OpenCVE Enrichment