Impact
The defect is a broken access control (CWE-862) in the WordPress Werkstatt theme that allows certain authenticated users to perform actions that should be restricted to higher‑privileged roles. The description notes that subscribers are affected, implying that a logged‑in subscriber can access protected theme functions. This could be leveraged to modify theme settings, potentially compromising site appearance or integrity and, if the theme exposes additional configuration options, enabling further compromise of the WordPress environment.
Affected Systems
Non‑vulnerable versions are not identified in the CVE data, but the text specifies that all releases of the Fuelthemes Werkstatt theme up to and including version 4.7.2 are affected. The flaw manifests on WordPress installations that have the theme active. No other WordPress components are mentioned as affected.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity. An EPSS score of less than 1% and the absence from the CISA KEV catalogue suggest that exploitation is not widespread or actively leveraged. The vulnerability requires that the attacker be authenticated as a subscriber or otherwise gain an account with publishing privileges, indicating a local account attack vector rather than pure remote exploitation. Consequently, users should prioritize updating the theme or mitigating access for subscriber roles.
OpenCVE Enrichment