Impact
The vulnerability in Cartify theme versions up to 1.3.0.1 allows unauthenticated actors to hijack user accounts due to a broken authentication mechanism. This flaw is identified as an improper authentication error (CWE-288). Attackers who exploit this can gain access to any user account on the site, potentially creating, deleting, or modifying site content and configuration.
Affected Systems
WordPress sites that have the AgniHD Cartify theme at or below version 1.3.0.1 are affected. Any site deploying this theme or earlier releases is vulnerable.
Risk and Exploitability
The CVSS score of 9.8 indicates a critical severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no publicly reported exploitation at this time. Based on the description, the flaw permits unauthenticated bypass of the theme’s authentication, enabling account takeover. The exact method of triggering the bypass is not detailed in the CVE description.
OpenCVE Enrichment