Impact
ThemeMove EduMall includes a missing authorization flaw that permits access to administrative features that should be guarded by proper role checks. The vulnerability arises from incorrectly configured access control levels, allowing users without the required permissions to reach sensitive areas of the theme.
Affected Systems
WordPress sites that use the EduMall theme from its initial release up to and including version 4.5.1.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves administrative functions that on the description, it is inferred that an attacker could exploit this by accessing those functions without proper permissions.
OpenCVE Enrichment