Executive brief
The MetroStore theme for WordPress contains a security flaw where it fails to properly check user permissions for certain actions. This could allow a logged-in user with low-level access, such as a subscriber, to perform actions or modify settings that should be restricted to administrators. Because the theme has not been updated recently, users are advised to replace it with a supported alternative to maintain site integrity.
Technical details
A missing authorization vulnerability (CWE-862) exists in the Sparkle WP MetroStore theme through version 1.3.2. The software fails to implement sufficient access control checks on certain functions, allowing an authenticated attacker with minimal privileges (such as a Subscriber) to execute actions intended for higher-privileged roles. The attack is reachable over the network without user interaction. As the theme is reportedly abandoned and has not received updates in over a year, no official patch is available, and security researchers recommend replacing the theme.
Affected products
- Sparkle WP MetroStore <= 1.3.2
Timeline
- 2022-09-24: other: Reported by researcher
- 2023-05-16: disclosed: Initial Patchstack publication
- 2026-06-11: advisory: NVD publication