Impact
This vulnerability is an Insecure Direct Object Reference flaw introduced in the WordPress WP Rentals theme due to incorrectly configured access control. It permits an attacker to use a user‑controlled key to access or modify resources that should otherwise be protected, potentially compromising data confidentiality and integrity. The weakness is classified as CWE‑639.
Affected Systems
It affects installations of the WP Rentals theme distributed by sc Internet Vivoo. All releases older than version 3.16.0 are impacted; any site still using those versions remains vulnerable until updated.
Risk and Exploitability
With a CVSS score of 5.4, the flaw is considered medium severity. The EPSS score is unavailable, so the precise probability of exploitation is unknown. The issue is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector involves an attacker manipulating identifiers in requests to bypass access controls, a technique that can be executed remotely via crafted HTTP calls. This inference follows from the stated "Authorization Bypass Through User‑Controlled Key" nature of the flaw.
OpenCVE Enrichment