Access Control Issues in Xtemos WoodMart Theme
CVE-2023-32240

5.4MEDIUM

Key Information:

Vendor
WordPress
Status
Vendor
CVE Published:
2 January 2025

Summary

The Xtemos WoodMart theme is susceptible to a missing authorization vulnerability that arises from incorrectly configured access control security levels. This flaw could allow unauthorized users to exploit certain functionalities or data access, thereby potentially compromising the integrity of the WordPress site relying on this theme. Users of WoodMart versions prior to 7.2.1 should be aware of this vulnerability and take necessary actions to reinforce their site's security against exploitation.

Affected Version(s)

WoodMart <= 7.2.1

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dave Jong (Patchstack)
.