Missing Authorization vulnerability in Betheme
CVE-2022-45349
4.3MEDIUM
Summary
A missing authorization vulnerability was identified in Muffingroup's Betheme theme for WordPress. This flaw permits unauthorized access to restricted areas of the application, impacting overall web security. Users of Betheme, especially those operating versions from n/a through 26.6.1, are at risk if proper mitigations are not implemented. It is crucial to take immediate steps to review and secure any unauthorized access points within their web applications.
Affected Version(s)
Betheme <= 26.6.1
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Dave Jong (Patchstack)