Impact
This vulnerability is a Missing Authorization flaw in the wpradiant Chocolate House WordPress theme. Key detail from the description: "Missing Authorization vulnerability ... allows Exploiting Incorrectly Configured Access Control Security Levels". Because it is a broken access control problem (CWE-862), an attacker may gain unauthorized access to functionality that should be restricted. The description does not explicitly state which functions are exposed or the consequences, so it is unclear whether an attacker could modify content, upload files, or view sensitive data; these are not confirmed by the supplied data.
Affected Systems
The affected product is the WordPress Chocolate House theme from vendor wpradiant. The CVE impact text shows that the issue applies to all releases from the first release through version 1.1.5, as noted: "Chocolate House: from n/a through <= 1.1.5". Therefore any site running Chocolate House 1.1.5 or earlier is affected.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk. The EPSS score is less than 1%, indicating a low chance of exploitation currently. The vulnerability is not listed in the CISA KEV catalog. The attack vector is not explicitly provided in the description; the likely route is through web requests to the theme’s administrative paths, but this is inferred rather than confirmed by the available information.
OpenCVE Enrichment