Impact
The vulnerability in the WordPress Woffice theme before version 5.4.33 is a missing authorization flaw that permits users to bypass intended security levels. An attacker can exploit this to access or modify content that should be restricted, effectively gaining elevated privileges within the site. The weakness is identified as CWE‑862 and results in unauthorized read, write, or administrative actions.
Affected Systems
Affected are deployments of the Woffice theme supplied by WofficeIO. Any installation of the theme older than version 5.4.33 is vulnerable. No specific configuration thresholds are mentioned; the issue exists across all deployed instances until the patch is applied.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity. No EPSS score is available and the vulnerability is not listed in CISA KEV. The attack vector is inferred to be remote through the web interface, as the flaw exists in the theme’s access control logic. Exploitation requires the attacker to reach a page or action that relies on the broken authorization, so a user with any browser access to those pages can benefit. Given the lack of a published exploit, the risk remains moderate but should not be ignored.
OpenCVE Enrichment