Impact
This vulnerability is a missing authorization flaw in the WordPress Royale News theme that allows attackers to perform actions that should be restricted. The flaw stems from incorrectly configured access control security levels, which can lead to unauthorized reading, modification, or deletion of content that should be protected. The weakness is identified as CWE-862, indicating a failure in authorization checks.
Affected Systems
The issue affects the Royale News WordPress theme version 2.2.4 and all earlier releases. Any website that still uses one of these versions of the theme is potentially vulnerable, regardless of other plugins or core WordPress updates. The vulnerability is isolated to the theme itself and does not involve the core platform.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, and the EPSS score of less than 1% suggests that exploitation is currently rare. The vulnerability is not listed in the CISA KEV catalog. The description does not state whether the attack requires authenticated access or a particular user role, so it is inferred that the missing authorization check could be exploited by any user who can send crafted requests to the website. Because the flaw is a missing authorization check, attackers who can access the site may leverage it without additional prerequisites.
OpenCVE Enrichment