Impact
The vulnerability is a missing authorization flaw in the StylemixThemes Motors WordPress theme, allowing an attacker to exploit incorrectly configured access control security levels. The flaw can lead to unauthorized viewing, modification, or deletion of protected content, risking data integrity for one or more users or the entire WordPress site. While an explicit attack vector is not given, such broken access control typically manifests through the web interface or theme‑related admin functions that accept credentials without proper role verification.
Affected Systems
All WordPress installations employing StylemixThemes Motors theme versions equal to or less than 1.4.108 are affected. The issue spans from the earliest unversioned release through 1.4.108, meaning any site that has not upgraded beyond this release is vulnerable.
Risk and Exploitability
The CVSS base score of 7.5 classifies the vulnerability as High severity. The EPSS score is not available, so the current exploitation probability cannot be quantified. The vulnerability is not listed in the CISA KEV catalog, indicating no known public exploits at the time of analysis. Likely, an attacker would gain access via the web interface, attempting to bypass role checks by using the theme’s administrative actions or by crafting requests that trigger the unsafe code paths. An attacker with any authenticated account, or potentially an unauthenticated user if the theme misconfigures default capability checks, could exploit the flaw without requiring additional privileges.
OpenCVE Enrichment