Impact
The vulnerability is a broken access control flaw in the raratheme Digital Download WordPress theme. It allows an attacker to bypass the theme’s incorrectly configured security levels, granting unintended access to protected content. This weakness is identified as CWE-862, representing missing authorization. The impact includes the potential for unauthorized viewing, download, or modification of digital assets that are meant to be restricted.
Affected Systems
Any WordPress site using the raratheme Digital Download theme up to and including version 1.1.4 is affected. The problem exists from the earliest release (n/a) through version 1.1.4. Updating to a newer, patched version eliminates the flaw.
Risk and Exploitability
The CVSS score is 5.3, indicating a medium severity. The EPSS score is less than 1%, and the vulnerability is not listed in the CISA KEV catalog, suggesting lower likelihood of widespread exploitation. Attackers would need to send crafted requests to the theme’s endpoints to exploit the access control bypass. No public exploit or known workaround is documented; therefore, the onus falls on the site administrator to apply the vendor patch to mitigate the risk.
OpenCVE Enrichment