Impact
This vulnerability is a Missing Authorization issue in raratheme The Minimal, allowing attackers to exploit incorrectly configured access control security levels. The result is a potential bypass of normal privilege restrictions, so an attacker could perform actions normally reserved for privileged users. The weakness is formally identified as CWE-862 (Missing Authorization).
Affected Systems
The Minimal theme for WordPress, version 1.2.9 and earlier, is affected. The CVE impact applies to all installations of the theme up to and including version 1.2.9; newer releases are not known to be affected.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is below 1%, implying a low probability that an exploit is actively used. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote, through a web-facing WordPress installation that has the vulnerable theme enabled and misconfigured access controls.
OpenCVE Enrichment