Impact
The Gillion WordPress theme up to version 4.13 has an unauthenticated broken access control vulnerability, identified as CWE‑862. An attacker can bypass normal authorization checks and gain unauthorized access to protected features or data that should require authentication. This flaw can be exploited to view, modify, or delete content, thereby impacting the confidentiality, integrity, and availability of the website.
Affected Systems
WordPress sites using Shufflehound’s Gillion theme version 4.13 or earlier are affected. The vulnerability exists in all installations of the theme through that release, regardless of other configuration settings.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity. An EPSS score of < 1% indicates a very low probability of exploitation, and the issue is not listed in the CISA KEV catalog, suggesting limited known exploitation. The likely attack vector is remote: an unauthenticated web user can craft requests to trigger the privileged actions exposed by the theme’s code.
OpenCVE Enrichment