Impact
A missing access check in YOOtheme Pro allows users with com_template editing rights to view data from any Joomla module, thereby exposing privileged configuration or sensitive content. This flaw represents a classic access control weakness (CWE‑284). The attacker can obtain information that may aid in further attacks such as social engineering or targeted exploitation of module features.
Affected Systems
The vulnerability affects the YOOtheme Pro extension for Joomla, versions 1.0.0 through 5.0.41. Users running any of these revision ranges are affected.
Risk and Exploitability
The CVSS score of 5.1 denotes moderate severity. Because the issue requires authenticated access and the EPSS is not available, the likelihood of exploitation is uncertain but potentially low. The vulnerability is not listed in CISA KEV, indicating no publicly known active exploitation. An attacker would need to be granted com_template editing permissions; no remote code execution or privilege escalation is described.
OpenCVE Enrichment