Impact
This vulnerability is a broken access control flaw in the VW Wedding WordPress theme that allows an attacker to bypass authorization checks for restricted content and administrative actions. The missing authorization creates a path for unauthenticated or low‑privilege users to read, modify, or delete theme configuration data, potentially altering site appearance, content, or compromising sensitive information. The weakness is identified as CWE‑862, highlighting improper access control enforcement.
Affected Systems
The vulnerability affects the VW Wedding theme developed by vowelweb, specifically versions 1.3.7 and earlier. Any WordPress site that has this theme installed and has not applied the update to a later, fixed version is susceptible.
Risk and Exploitability
The CVSS score of 5.3 places this issue in the medium severity range, indicating a reasonable risk level. The EPSS score of less than 1% suggests a low probability of exploitation in the wild. It is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is a web‑based request to the affected WordPress installation, where an attacker can exploit the missing authorization to gain unauthorized access to sensitive theme functions.
OpenCVE Enrichment