Impact
The Cream Magazine theme for WordPress contains a missing authorization flaw that allows attackers to exploit incorrectly configured access control security levels. The weakness permits unauthorized users to access functionality reserved for privileged users, potentially enabling unauthorized configuration changes, data leakage, or further compromise of the site. Because the flaw is a broken access control (CWE‑862), any exposed administrative endpoints can be accessed without proper authentication or authorization.
Affected Systems
Themebeez’s Cream Magazine theme, versions up through 2.1.10, is affected. The vulnerability applies to all installations running any of those versions and does not include newer releases beyond 2.1.10.
Risk and Exploitability
The issue has a CVSS score of 5.3, indicating moderate severity, and an EPSS score of less than 1 %, meaning the likelihood of exploitation is currently very low. The vulnerability is not listed in the CISA KEV catalog. Attackers could exploit the flaw by sending crafted HTTP requests to the theme’s administrative endpoints, possibly without needing prior authentication. Because it concerns access control, the risk is higher for sites with exposed admin interfaces.
OpenCVE Enrichment