Impact
An unauthenticated broken access control flaw exists in the Grand News WordPress theme versions 3.4 and earlier. The vulnerability allows an attacker to bypass standard permission checks and obtain administrative capabilities. This could enable the attacker to read, modify, or delete content, alter site settings, or execute other privileged actions, thereby compromising confidentiality, integrity, and availability of the affected WordPress site.
Affected Systems
The flaw affects the Grand News theme from ThemeGoods. All WordPress installations running Grand News version 3.4 or earlier are vulnerable. Site owners should verify the theme version and update if necessary.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity. No EPSS data is available, and the vulnerability is not listed in CISA KEV. The attack vector is likely remote, through standard web requests, which is inferred from the description of an unauthenticated access issue. Successful exploitation would allow an attacker to gain unauthorized administrative privileges with no authentication required.
OpenCVE Enrichment