Executive brief
The Startupzy theme for WordPress contains a security flaw where it fails to properly check user permissions for certain actions. This could allow a logged-in user with low-level access, such as a subscriber, to perform actions or modify settings they should not be authorized to change. While the impact is considered low, it represents a breakdown in the site's internal security boundaries.
Technical details
A Missing Authorization (CWE-862) vulnerability exists in the Jegstudio Startupzy theme for WordPress through version 1.1.1. The flaw stems from incorrectly configured access control security levels, where the application fails to validate if a user has the necessary privileges before executing specific functions. An attacker authenticated with low-level privileges (e.g., Subscriber) can exploit this over the network to perform unauthorized modifications or actions. The issue is addressed in version 1.1.2.
Affected products
- Jegstudio Startupzy n/a through 1.1.1
Timeline
- 2024-01-20: disclosed: Reported by Dhabaleshwar Das
- 2024-04-26: advisory: Patchstack published advisory details
- 2026-06-17: other: CVE record published/updated in NVD