Impact
The vulnerability is a missing authorization flaw in the raratheme Elegant Pink theme, which allows an attacker to exploit incorrectly configured access control settings. This broken access control is categorized as CWE-862 and can enable unauthorized users to invoke privileged functions within the WordPress site, potentially leading to data tampering or the execution of administrative actions that should be restricted.
Affected Systems
Affected product is raratheme Elegant Pink, impacting all installations from an unspecified starting version up to and including version 1.3.3. No specific patch level is listed beyond the vulnerability affecting releases <= 1.3.3.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk; the EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, suggesting low current exploitation likelihood. The exact attack vector is not detailed in the public description, but it is inferred that access is gained via the theme's administrative interface or functions exposed to logged-in users. An attacker able to bypass normal permission checks could gain elevated privileges within the WordPress environment.
OpenCVE Enrichment