Executive brief
The Vireo WordPress theme contains a broken access control vulnerability that allows users with subscriber-level privileges to access pages or perform actions they should not be authorized to perform. An attacker with a low-level account could view other users' data or trigger unauthorized administrative functions, potentially compromising site security and user privacy.
Technical details
This is a broken access control vulnerability (CWE-639) in the Vireo WordPress theme that fails to properly validate user authorization when accessing protected resources. The vulnerability requires an authenticated user with subscriber-level permissions to exploit; an attacker can craft requests to bypass security checks and access data or functionality reserved for higher-privilege accounts. The issue affects Vireo versions up to and including 1.0.37. No official patch is currently available, and the theme has not received updates in over a month, indicating that a fix is unlikely to be forthcoming. Affected sites should remove the theme or implement access control mitigation rules.
Affected products
- extendthemes Vireo <= 1.0.37
Timeline
- 2025-10-20: disclosed: Vulnerability reported to Patchstack
- 2025-12-31: advisory: Published by Patchstack and disclosed publicly