Impact
The reported flaw is an unauthenticated broken access control vulnerability in versions of the Manual – Documentation, Knowledge Base & Education WordPress theme up to 7.5.4. The weakness permits an actor who does not have a valid WordPress account to reach and invoke administrative functionality that is intended to be restricted, potentially allowing the actor to perform privileged theme‑level operations. This flaw maps to CWE‑862 and could be used to gain higher privileges in the WordPress installation without authentication.
Affected Systems
The vulnerability applies to any WordPress site that has the Pixelacehq Manual – Documentation, Knowledge Base & Education WordPress theme installed with a version number 7.5.4 or earlier. Sites deploying those releases are in scope and could be exposed if the theme's administrative interfaces are accessible to unauthenticated users.
Risk and Exploitability
The flaw carries a CVSS score of 7.5, indicating a high severity impact. Its EPSS score is reported as less than 1%, suggesting a very low current exploitation probability. The issue is not listed in the CISA KEV catalog. Based on the nature of the vulnerability, the likely attack vector is unauthenticated HTTP requests to theme‐controlled administrative URLs that lack proper authentication checks; an attacker could exploit this by sending such requests to the affected WordPress site.
OpenCVE Enrichment