Impact
The vulnerability is an unauthenticated broken access control flaw in versions of the Anders Norén Koji theme up to 2.2.1. It allows attackers to perform actions that should be restricted to authenticated users, exposing the site to unauthorized operations. The weakness corresponds to missing permission enforcement (CWE-862).
Affected Systems
The Koji theme version 2.2.1 or earlier installed on WordPress sites is affected. Any WordPress site using these theme versions is vulnerable regardless of other security settings.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is unauthenticated requests to theme‑related endpoints that lack proper access restrictions, as the description states that the flaw allows unauthenticated use of privileged functions.
OpenCVE Enrichment