Junglewise Threat Intelligence

CVE-2025-53302: Anton Shevchuk Constructor missing authorization in WordPress theme

CVE-2025-53302 · Severity: medium · CVSS 5.3 · Published 2026-06-02

Technologies: Anton Shevchuk Constructor.

Executive brief

The Constructor theme for WordPress contains a security flaw that allows unauthorized users to access certain internal functions. This occurs because the theme does not properly check if a user has the correct permissions before allowing them to interact with specific features. While the impact is considered low, it could potentially allow unauthenticated visitors to view information or perform actions intended only for site administrators.

Technical details

A missing authorization vulnerability (CWE-862) exists in the Anton Shevchuk Constructor theme for WordPress through version 1.6.5. The issue stems from a failure to implement proper Access Control Lists (ACLs) or permission checks on specific theme functions. An unauthenticated remote attacker can exploit this by sending crafted requests to the server to trigger these functions. This can lead to unauthorized access to restricted functionality or information disclosure. As of the advisory date, no official patch has been released.

Affected products

  • Anton Shevchuk Constructor n/a through 1.6.5

Timeline

  • 2025-05-28: other: Reported by Sulabh Jain
  • 2025-06-27: advisory: Early warning and publication by Patchstack
  • 2026-06-02: disclosed: NVD publication date

References