Impact
A missing authorization check in the raratheme Education Zone WordPress theme allows an attacker to bypass normal access controls and reach areas that should be restricted. This vulnerability can enable unauthorized users to view or modify sensitive site content, configuration settings, or administrative functions, potentially leading to defacement, data leakage, or further compromise. The weakness is a classic Missing Authorization issue, identified as CWE‑862.
Affected Systems
The flaw exists in all installations of the raratheme Education Zone theme up to and including version 1.3.8. WordPress sites that have not yet upgraded to a patched version—typically those running versions of the theme from its initial release through 1.3.8—are affected.
Risk and Exploitability
The CVSS base score of 6.5 indicates a medium severity vulnerability. The EPSS score of less than 1 % suggests that exploitation of this flaw is unlikely to be widespread at present, and the vulnerability is not yet recorded in the CISA KEV catalog. While the exact attack vector is not detailed in the description, the missing authorization check implies that an unauthenticated or low‑privileged user could exploit the flaw remotely by submitting crafted requests to the site. Deployment of a patch or update is therefore strongly recommended.
OpenCVE Enrichment