Impact
The vulnerability is a missing authorization flaw in the VW School Education WordPress theme. Because of incorrectly configured access control, an attacker can gain access to resources that should be protected. This flaw is a classic "Missing Authorization" issue (CWE‑862). The potential impact is unauthorized reading, modification, or deletion of data within the WordPress installation, which could lead to disclosure of sensitive information or content tampering.
Affected Systems
Affects the VW School Education theme from vowelweb. All installations using version 1.4.6 or any earlier version are vulnerable. Versions newer than 1.4.6 are not affected as per the vendor’s notice.
Risk and Exploitability
The CVSS score is 5.3, indicating a moderate risk level. The EPSS score is less than 1%, suggesting the likelihood of exploitation is low. The vulnerability is not listed in the CISA KEV catalog, which further implies it is not a currently known, actively exploited issue. The vulnerability is exposed via the theme’s web interface, so an attacker with web access to the WordPress site could attempt exploitation; this inference is based on the typical deployment of WordPress themes.
OpenCVE Enrichment