Impact
The vulnerability is an unauthenticated broken access control flaw that allows an attacker to bypass normal authorization checks for the WordPress Nokri theme. Because authentication is not required, an attacker can potentially view or modify resources that should be restricted, such as private content or theme settings. The flaw is represented by CWE-640, indicating a failure to properly enforce access control constraints. Without remediation, this could compromise the confidentiality, integrity, or availability of site data and user information.
Affected Systems
WordPress installations that have the Nokri theme version 1.6.6 or earlier. The theme is distributed by the scriptsbundle vendor under the Nokri product line. Any site using these versions of the theme is considered affected until an update to at least 1.6.7 is performed.
Risk and Exploitability
The CVSS score of 9.8 classifies this issue as critical, reflecting a high likelihood of exploitation and severe impact. EPSS information is not available, suggesting no publicly known samples yet, but the absence of a KEV listing does not diminish the potential risk. The vulnerability is remotely exploitable via the web interface, with no authentication required, making it accessible to any visitor on the internet. Given the critical severity and remote nature, the likelihood of attack remains significant until the theme is upgraded.
OpenCVE Enrichment