Impact
The vulnerability stems from a missing authorization Corner WordPress theme. This broken access control allows an attacker to access or modify theme configurations and data that should be restricted to privileged users, potentially exposing sensitive information or altering site appearance. The weakness is classified as CWE‑862, indicating an authorization failure that could compromise data integrity or confidentiality.
Affected Systems
All installations of the vowelweb VW Food Corner theme with a version of 1.1.0 or earlier are susceptible. The affected product is the WordPress theme "VW Food Corner" by vowelweb; users should check the theme version and apply any available update that addresses the authorization issue.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact. The EPSS score is below 1%, implying a low probability that this flaw is currently exploited in the wild, and the vulnerability is not listed in the CISA KEV catalog. Thus, while the risk is moderate, the likelihood of exploitation is low. Based on the description, it is inferred that the attack vector involves an attacker already having some level of access to the WordPress site, as the flaw pertains to theme configuration pages site with the vulnerable theme, they can potentially read or alter theme data without proper privilege checks.
OpenCVE Enrichment