Impact
Based on the description, it is inferred that an unauthenticated broken access control flaw in the Photography theme allows anyone who can reach the WordPress site to invoke actions that are normally restricted to privileged users, such as editing or deleting posts, media, or theme settings. The weakness is identified as CWE‑862: Broken Access Control. This directly threatens the confidentiality, integrity, and availability of the site’s content and configuration. The impact is therefore the potential loss or corruption of data and compromise of the site’s functionality.
Affected Systems
Based on the description, it is inferred that the flaw affects WordPress installations using the Photography theme from ThemeGoods version 7.7.6 and earlier. Site owners must confirm the exact theme version; if they are using a version in this range, the vulnerability is present.
Risk and Exploitability
Based on the description, it is inferred that the vulnerability can be exploited remotely via the WordPress site web interface. The CVSS score of 5.3 indicates a moderate severity. The EPSS score of less than 1% suggests that the likelihood of exploitation is currently very low. The vulnerability is unauthenticated, implying that an attacker could exploit this flaw remotely through the web interface without needing a valid user account. The weakness is not known to be currently exploited in the wild and is not listed in CISA’s KEV catalog.
OpenCVE Enrichment