Access Control Weakness in Acerola Theme by themeton
CVE-2025-31066
5.3MEDIUM
What is CVE-2025-31066?
The Acerola theme by themeton has a significant access control vulnerability that allows unauthorized users to exploit incorrectly configured access levels. This security flaw affects all versions from its initial release up to 1.6.5, creating potential risks for web administrators who may not have set proper access controls. Users of this theme should take immediate action to review their security configurations to mitigate possible exploitation.
Affected Version(s)
Acerola <= 1.6.5
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) (Patchstack Alliance)