Impact
The homlisti theme through version 3.1.2 contains a broken access control flaw that allows a user with Subscriber role to gain unauthorized access to functionality or data beyond what the role is intended. This weakness can lead to unauthorized viewing or modification of content or sensitive information that is normally restricted to higher‑privileged users. The flaw is identified as CWE‑862, representing improper authorization checks in the application logic.
Affected Systems
The vulnerability affects WordPress installations that use the RadiusTheme Homlisti theme version 3.1.2 or earlier. Users running any of these affected WordPress themes on their sites are susceptible, regardless of the overall WordPress version or other plugins.
Risk and Exploitability
The CVSS score of 6.5 categorizes the issue as a moderate severity vulnerability. The EPSS score is currently not available, so the likelihood of exploitation cannot be quantified, and the vulnerability is not listed in CISA KEV. Given that the flaw resides in a WordPress theme, the likely attack vector is a web‑based exploitation, where an authenticated subscriber can trigger the exposed functions via on‑site requests. The exact exploitation conditions are not fully detailed, but any authenticated user with a Subscriber role may be able to perform the unauthorized action if the theme’s access checks are bypassed.
OpenCVE Enrichment