Impact
The vulnerability is an unauthenticated broken access control flaw in the Chaplin WordPress theme through version 2.6.8. It can allow an attacker to perform privileged operations that should be restricted to authenticated users, potentially leading to unauthorized configuration changes or worse. This weakness is classified as CWE‑862.
Affected Systems
The affected product is the WordPress Chaplin Theme by Anders Norén. Versions 2.6.8 and earlier are impacted; later releases contain the fix.
Risk and Exploitability
The CVSS score of 7.5 places the flaw in the high‑severity category. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog, suggesting no confirmed public exploits yet. The attack vector is likely web‑based, with no authentication required, meaning any attacker able to reach the site could exploit the flaw by requesting the privileged URLs exposed by the theme.
OpenCVE Enrichment