Impact
The vulnerability is a missing authorization flaw in the vowelweb VW Photography theme that allows an attacker to manipulate incorrectly configured access control security levels. The weakness, identified as CWE-862, enables unauthorized users to perform actions that should require proper authentication or authorization, potentially exposing or altering site content.
Affected Systems
All WordPress sites using the vowelweb VW Photography theme from the earliest release through version 1.3.8 are affected. Any installation of this theme, regardless of other plugins or configurations, is vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while an EPSS score of less than 1% suggests low likelihood of widespread exploitation at present. The flaw is not listed in the CISA KEV catalog. Based on the description, exploitation would most likely occur via web requests to the theme’s administrative endpoints, requiring only access to the vulnerable site’s web interface. No official vendor patch is listed, only an upgrade recommendation.
OpenCVE Enrichment