Junglewise Threat Intelligence

CVE-2024-33685: Jegstudio Startupzy missing authorization in WordPress theme

CVE-2024-33685 · Severity: medium · CVSS 4.3 · Published 2026-06-17

Executive brief

The Startupzy theme for WordPress contains a security flaw where it fails to properly check user permissions for certain actions. This could allow a logged-in user with low-level access, such as a subscriber, to perform actions or modify settings they should not be authorized to change. While the impact is considered low, it represents a breakdown in the site's internal security boundaries.

Technical details

A Missing Authorization (CWE-862) vulnerability exists in the Jegstudio Startupzy theme for WordPress through version 1.1.1. The flaw stems from incorrectly configured access control security levels, where the application fails to validate if a user has the necessary privileges before executing specific functions. An attacker authenticated with low-level privileges (e.g., Subscriber) can exploit this over the network to perform unauthorized modifications or actions. The issue is addressed in version 1.1.2.

Affected products

  • Jegstudio Startupzy n/a through 1.1.1

Timeline

  • 2024-01-20: disclosed: Reported by Dhabaleshwar Das
  • 2024-04-26: advisory: Patchstack published advisory details
  • 2026-06-17: other: CVE record published/updated in NVD

References