Junglewise Threat Intelligence

CVE-2025-53999: Altair Theme broken access control vulnerability

CVE-2025-53999 · Severity: medium · CVSS 6.5 · Published 2026-08-20

Executive brief

Altair is a WordPress theme that contains an unauthenticated broken access control flaw allowing attackers to bypass authorization checks and access restricted pages or perform unauthorized actions. This vulnerability enables unauthorized data exposure and account compromise, and is expected to be actively exploited in mass campaigns targeting WordPress sites.

Technical details

The vulnerability is a broken access control issue in Altair WordPress theme versions 5.2.2 and earlier, exploitable without authentication. The flaw allows attackers to access protected pages, view sensitive user data, or perform actions that should be restricted to authorized users. The attack vector is network-based and requires no special privileges or user interaction. As of the advisory date, no official patch has been released; Patchstack has issued a mitigation rule to block attack attempts.

Affected products

  • Altair Altair Theme 5.2.2 and earlier

Timeline

  • 2026-08-19: disclosed: Vulnerability reported by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity)
  • 2026-08-20: advisory: CVE-2025-53999 published on NVD

References