Impact
The vulnerability is a missing authorization in the WordPress Numinous theme, classified as a broken access control issue (CWE-862). It allows attackers to access or perform privileged operations within the theme without proper authentication or authorization. This could enable unauthorized content modification, configuration changes, or other administrative actions within the WordPress site.
Affected Systems
The issue affects the raratheme Numinous theme for WordPress, with all releases up to and including version 1.3.0. The vendor identified is raratheme and the product is Numinous.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity assessment. An EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote, via the WordPress web interface or crafted requests to the theme’s endpoints, exploiting incorrectly configured access control levels. No evidence in the input indicates that higher privilege escalation to the underlying OS is required or possible.
OpenCVE Enrichment