Impact
This vulnerability is a Missing Authorization flaw in the raratheme Book Landing Page WordPress theme. It permits exploitation of incorrectly configured access control security levels, allowing an attacker to access or modify theme configuration and potentially perform privileged actions without proper authorization. The weakness is identified as CWE-862.
Affected Systems
The affected product is the raratheme Book Landing Page WordPress theme. All released versions up to and including 1.2.7 are impacted, with the confirmation range listed as "from n/a through <= 1.2.7." There is no lower bound specified, so any site using any version of the theme not newer than 1.2.7 should be considered vulnerable.
Risk and Exploitability
The CVSS base score is 5.3, indicating a moderate risk that could lead to breaches of confidentiality, integrity, or availability if exploited. The EPSS score is less than 1%, suggesting a low probability of exploitation in the near term, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is via the web interface, where an unauthenticated or low-privilege user could utilize the theme’s administrative functions. No prerequisite conditions are provided in the data, so the risk level remains moderate with a low exploitation likelihood.
OpenCVE Enrichment