What the vulnerability does
01Description
Unauthenticated Broken Access Control in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
What the vulnerability does
Unauthenticated Broken Access Control in Manual - Documentation, Knowledge Base & Education WordPress Theme <= 7.5.4 versions.
Explanation of Vulnerability in Simple Terms
The Manual WordPress theme through version 7.5.4 lacks proper authorization checks, allowing unauthenticated attackers to read sensitive information. An attacker can access restricted data without logging in or providing credentials. This affects confidentiality but not data integrity or availability. Site administrators should update immediately to a patched version.
What an attacker can do
Read sensitive information without logging in or providing any credentials.
Potential impact on your site
Unauthorized visitors can access restricted content or data meant for authenticated users only.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities