Impact
A missing authorization check in the vowelweb VW Fitness WordPress theme allows users to exploit incorrectly configured access control security levels. Because the theme does not enforce proper privileges, an attacker could access or modify content that should be restricted to administrators or authorized users. This weakness is categorized as CWE-862, indicating a lack of authentication checks. The potential impact includes unauthorized disclosure, tampering, or creation of data within the WordPress site.
Affected Systems
The vulnerability affects the VW Fitness theme from vowelweb. It applies to all releases up to and including version 4.3.4, as noted in the vendor statement. No later versions are listed, implying that higher revisions are assumed to be fixed.
Risk and Exploitability
The CVSS score of 5.3 places this vulnerability in the moderate range, while an EPSS score of less than 1% suggests a low likelihood of active exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is the web application layer, with an attacker sending authenticated or unauthenticated requests to privileged endpoints that lack proper authorization checks. The exploitation would require access to the WordPress site and knowledge of the vulnerable theme's administrative functions.
OpenCVE Enrichment