What the vulnerability does
01Description
Improper Privilege Management vulnerability in Themify Themify Ultra allows Privilege Escalation.This issue affects Themify Ultra: from n/a through 7.3.5.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Improper Privilege Management vulnerability in Themify Themify Ultra allows Privilege Escalation.This issue affects Themify Ultra: from n/a through 7.3.5.
Explanation of Vulnerability in Simple Terms
Themify Ultra versions up to 7.3.5 contain a privilege management flaw that allows authenticated users with low-level access to perform actions reserved for administrators. An attacker with a standard user account can read sensitive data, modify site content, or disrupt service without requiring additional interaction. Sites running affected versions should update immediately.
What an attacker can do
Read sensitive data, modify content, or disrupt the site using a low-privilege user account.
Potential impact on your site
Any registered user can escalate their permissions and access admin functions, compromising site integrity and confidentiality.
Conditions required to exploit
Attacker must have a valid low-privilege user account on the site.
Key dates
External resources
Related vulnerabilities