Impact
The vulnerability is a missing authorization flaw (CWE‑862) in the raratheme Pranayama Yoga WordPress theme. It allows an attacker to bypass properly configured access controls and gain unauthorized access to protected administrative areas. As a result, the attacker could read, modify, or delete site content and configuration settings that should be restricted, compromising confidentiality, integrity, and potentially availability of the website.
Affected Systems
Affected product: raratheme Pranayama Yoga theme, version 1.2.2 and all earlier releases. No specific patch version is indicated in the CVE source, so every version up to and including 1.2.2 is considered vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in CISA's KEV catalog, implying no known widespread attacks. The likely attack vector is web‑based, requiring an attacker to construct and send requests targeting administrative endpoints that lack sufficient authorization checks. No additional exploitation prerequisites are stated in the CVE data.
OpenCVE Enrichment