Impact
Avada Custom Branding plugin versions 1.2 and earlier expose a broken access control flaw that allows trusted users to alter branding settings. The vulnerability is classified as CWE‑862, indicating a failure to enforce proper authorization. An attacker who can authenticate to the WordPress administration interface could potentially modify site header logos or other visual elements, thereby misleading visitors or facilitating social‑engineering or phishing attacks. The description does not explicitly state the attack vector; it is inferred that an authenticated user with sufficient permissions is required to exploit the flaw.
Affected Systems
The flaw affects the WordPress plugin published by ThemeFusion, named Avada Custom Branding, in all releases with a version number of 1.2 or earlier. WordPress installations that integrate these plugin versions are exposed, regardless of the host server configuration or other plugins in use.
Risk and Exploitability
The CVSS score of 4.3 represents a moderate risk level. An EPSS score of less than 1% suggests the probability of exploitation is very low at present. The vulnerability is not listed in the CISA KEV catalog, meaning no confirmed operational exploit has been reported. While the authentication requirement is explicit, the specific WordPress roles that can trigger the flaw are not formally documented; it is inferred that users with editor or contributor capability may be affected due to the nature of the plugin’s settings page. Defenders should treat this as a moderate threat that merits timely mitigation.
OpenCVE Enrichment