Missing Authorization Vulnerability in FameThemes OnePress Theme
CVE-2025-22643
4.3MEDIUM
Summary
A missing authorization vulnerability has been identified in the FameThemes OnePress theme, which could be exploited by attackers due to incorrectly configured access control security levels. This issue allows unauthorized users to gain access to restricted areas of the site, potentially compromising sensitive information or functionality. The affected versions include OnePress from n/a through 2.3.11, emphasizing the need for users to update their installations to safeguard against potential attacks.
Affected Version(s)
OnePress <= 2.3.11
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Fariq Fadillah Gusti Insani (Patchstack Alliance)