Impact
Missing Authorization vulnerability in raratheme Bakes And Cakes allows attackers to bypass configured access control and perform actions that should be restricted, leading to unauthorized data access or modification. The weakness is a classic missing authorization flaw (CWE‑862).
Affected Systems
Vendor raratheme Bakes And Cakes theme, versions up to and including 1.2.9 are affected
Risk and Exploitability
The vulnerability has a CVSS score of 5.3 and an EPSS score below 1 %. It is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is through the WordPress web interface, where an unauthenticated or insufficiently privileged user can invoke protected functionality. An attacker who can reach the theme’s endpoints could gain unauthorized access to site data or administrative functions, depending on the level of access required by those endpoints.
OpenCVE Enrichment