Impact
The vulnerability in the kutethemes Biolife theme arises from missing authorization controls that allow attackers to exploit incorrectly configured access levels. This flaw enables the execution of arbitrary WordPress shortcodes, which can be leveraged to insert malicious code or content into a site’s output. The weakness is identified as a missing access control (CWE‑862). In effect, an attacker can potentially run any shortcode they supply, leading to unauthorized code execution and significant compromise of content and site integrity.
Affected Systems
The affected product is the Biolife WordPress theme from kutethemes. All releases from the initial version through 3.2.3 are susceptible. Users running any of these versions on a WordPress installation are at risk, regardless of site size or audience.
Risk and Exploitability
Given the lack of publicly available CVSS and EPSS scores, the risk can be inferred to be high, as the flaw permits code execution without authentication. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed exploitation yet, but the potential impact remains severe. The likely attack vector involves an adversary gaining the ability to inject or modify shortcodes via the theme’s interfaces or by manipulating input that triggers shortcode processing. Exploitation requires no special privileges and can be performed by anyone with access to the sites using the vulnerable theme.
OpenCVE Enrichment