Impact
The Open Shop WordPress theme contains a missing authorization flaw that allows attackers to exploit incorrectly configured access control levels. As a result, a user who can invoke the vulnerable code paths may gain unauthorized read, modify, or delete capabilities over the site’s content. Based on the description, the vulnerability is a classic broken access control weakness as defined by CWE-862, and the likely attack requires the attacker to interact with the site’s theme layer, though the exact user privilege needed is not specified in the data.
Affected Systems
WordPress sites that have installed the Open Shop theme version 1.7.1 or earlier are affected. The theme, provided by themehunk, is vulnerable in all releases from the initial version up through 1.7.1, so any site using any of those releases should review its theme configuration and version.
Risk and Exploitability
The CVSS score of 7.1 classifies the issue as high severity, while the EPSS score of <1% indicates a very low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Exploitation would involve targeting a WordPress installation that has the Open Shop theme active and relying on the theme’s flawed access‑control implementation; no publicly documented exploit exists, but the flaw could enable privilege escalation if an attacker can trigger the vulnerable code.
OpenCVE Enrichment