Impact
The vulnerability is a broken access control flaw that affects all releases up to and including version 3.2.8 of the Martfury – WooCommerce Marketplace WordPress Theme. It allows users with the Subscriber role to bypass intended restrictions in the theme’s functionality, potentially allowing them to access or manipulate elements that should otherwise be protected. The issue is classified as CWE‑862, an authorization weakness; based on the description, it is inferred that the vulnerability could expose administrative capabilities to a lower‑privileged user.
Affected Systems
The affected products are the Martfury – WooCommerce Marketplace WordPress Theme developed by Drfuri; any installations using version 3.2.8 or earlier are susceptible. Versions newer than 3.2.8 are not impacted.
Risk and Exploitability
The CVSS score of 4.3 indicates a low to moderate severity, and the EPSS score of less than 1% suggests a very low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to possess a Subscriber account and exploit the theme’s oversight of access controls; based on the nature of broken access control, the likely attack vector may involve sending crafted requests or interacting with exposed theme interfaces. Because the exact privileges gained are not detailed in the data, the precise scope of damage remains uncertain, but the risk of unintended access to theme settings is evident.
OpenCVE Enrichment