Impact
A missing authorization check in the Frenify Guff WordPress theme allows an attacker to exploit incorrectly configured access control levels. The vulnerability can enable a user who should not have certain permissions to access protected administrative functions or sensitive content, potentially leading to data exposure or further exploitation of the site.
Affected Systems
WordPress sites using the Guff theme version 1.0.1 or earlier are affected. The issue is reported for all releases from the earliest version through 1.0.1. No further sub‑version details are available beyond this upper bound.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity with potential for significant impact if the flaw is abused. The EPSS score is very low (<1 %), suggesting that attackers are unlikely to target this weakness at present, and it is not currently listed in the CISA KEV catalog. The next likely attack vector, inferred from the description, is through the WordPress web interface where an attacker could send crafted requests that bypass the authorization check. The risk remains elevated until the theme is updated or mitigations are applied.
OpenCVE Enrichment