Impact
The Civi theme for WordPress (uxper) suffers from an unauthenticated broken access control flaw (CWE‑862). The flaw allows a visitor to reach administrative or privileged functions that should require authentication, potentially enabling the creation of content or modification of settings that are normally reserved for administrators. Unchecked access leads to unauthorized manipulation and exposure of sensitive configuration.
Affected Systems
The vulnerability affects the Civi theme version 2.2.4 and all earlier releases. The vendor uxper has not specified a fixed version, so any release newer than 2.2.4 should be verified for a patch. WordPress plugins or themes that have not been updated beyond this point remain vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact, whereas the EPSS score of < 1% reflects a low probability of exploitation. The issue is not in the CISA KEV catalog, implying no widespread known exploits. Attackers likely target unauthenticated HTTP endpoints that incorrectly bypass authentication checks, which is inferred from the description of broken access control.
OpenCVE Enrichment