Impact
The vulnerability is a missing authorization flaw that allows attackers to bypass the access control mechanisms of the WordPress Fascinate theme. The flaw arises from incorrectly configured security levels, which lets an unauthorized user gain access to restricted administrative functions or content. This is classified as a CWE-862 authorization error and can lead to unauthorized content modification or escalation of privileges within the site.
Affected Systems
Themebeez Fascinate theme for WordPress, specifically any installation of version 1.1.5 or earlier. The issue is present across all versions from the earliest available release up to and including 1.1.5.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity impact. The EPSS score of less than 1% suggests that the probability of exploitation is low and the vulnerability is uncommon in the wild. It is not listed in CISA’s KEV catalogue. The lack of detailed exploitation steps in the description means the attack vector is inferred to involve UI or URL manipulation to reach the vulnerable administrative pages, potentially exploiting incorrectly set role permissions.
OpenCVE Enrichment