Impact
The vulnerability is a broken access control flaw (CWE‑862) in the Fuelthemes Werkstatt WordPress theme. It allows any logged‑in subscriber to perform actions beyond the permissions normally granted to that role, effectively elevating privileges within the theme's scope.
Affected Systems
The issue impacts the Fuelthemes Werkstatt theme on WordPress sites for all theme versions up to and including 4.7.2, regardless of the WordPress core version.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. The EPSS score of less than 1% and absence from the KEV catalog suggest that exploitation is unlikely to be widespread. The flaw appears to be exploitable by any logged‑in subscriber, implying a local account access attack vector rather than remote exploitation.
OpenCVE Enrichment