Impact
The vulnerability in Omegathemes Grocery Shopping Store theme versions up to 1.3.3 allows an unauthenticated attacker to bypass authentication by exploiting the Password Recovery path or channel. The flaw is an Identity and Authentication weakness (CWE-288) that can let an attacker obtain administrative or site‑wide access without legitimate credentials, potentially compromising confidentiality, integrity and availability of the site.
Affected Systems
Omegathemes’ Grocery Shopping Store WordPress theme is affected in all releases from the first public version through 1.3.3. Any WordPress installation using this theme with a version of 1.3.3 or earlier is at risk.
Risk and Exploitability
The CVSS v3.1 score of 7.1 indicates a high severity of this authentication bypass. Although the EPSS score is not available, there is no indication that it is mitigated, so exploitation probability is uncertain but potentially significant. The vulnerability is not listed in the CISA KEV catalog. Attackers likely utilize the password recovery form or alternate URLs to craft an authenticated session without a valid password. Given that the flaw resides in the theme code, it can be exploited from any network location that can access the public password recovery endpoint.
OpenCVE Enrichment