Impact
Missing authorization in the raratheme Spa and Salon WordPress theme permits attackers to bypass access controls, potentially allowing the reading, creation, or modification of content, settings, or files that should be protected. The flaw arises from incorrectly configured security levels, enabling privilege escalation within the site and leading to possible data exposure, unauthorized changes, or further compromise.
Affected Systems
All WordPress sites that use raratheme’s Spa and Salon theme up to and including version 1.3.2 are vulnerable. The theme, developed by Raratheme, is commonly deployed in spa, salon, and beauty‑related websites.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score is below 1%, reflecting a low likelihood of exploitation at this time. The vulnerability is not listed in CISA’s KEV catalog. While the official documentation does not specify an attack vector, it is inferred that attackers could exploit the missing authorization via the website’s front‑end or back‑end interfaces where the theme’s permission checks are insufficient. The actual risk depends on how tightly the site’s user roles and file permissions are configured.
OpenCVE Enrichment