Impact
The vulnerability is a failed authorization check in versions up to 4.2.2 of the WordPress TemplateSpare plugin, creating a broken access control flaw. A logged‑in user with subscriber privileges can perform actions that should be limited to higher roles, potentially exposing or altering protected content. This CWE‑862 issue permits an escalation of privileges within the application.
Affected Systems
The flaw affects WordPress sites that have the TemplateSpare plugin installed in any version 4.2.2 or earlier. The affected vendor is Templatespare and the product is the TemplateSpare plugin, which is used for customizing WordPress themes and templates.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score of less than 1% shows very low likelihood of exploitation. It is not listed in CISA KEV. The attack vector appears to require an authenticated subscriber account; no evidence suggests remote code execution or external exploitation. An attacker could misuse subscriber privileges to advance privileges or access restricted content, but the risk remains within these bounds.
OpenCVE Enrichment