Junglewise Threat Intelligence

CVE-2025-62751: extendthemes Vireo broken access control

CVE-2025-62751 · Severity: medium · CVSS 4.3 · Published 2025-12-31

Executive brief

The Vireo WordPress theme contains a broken access control vulnerability that allows users with subscriber-level privileges to access pages or perform actions they should not be authorized to perform. An attacker with a low-level account could view other users' data or trigger unauthorized administrative functions, potentially compromising site security and user privacy.

Technical details

This is a broken access control vulnerability (CWE-639) in the Vireo WordPress theme that fails to properly validate user authorization when accessing protected resources. The vulnerability requires an authenticated user with subscriber-level permissions to exploit; an attacker can craft requests to bypass security checks and access data or functionality reserved for higher-privilege accounts. The issue affects Vireo versions up to and including 1.0.37. No official patch is currently available, and the theme has not received updates in over a month, indicating that a fix is unlikely to be forthcoming. Affected sites should remove the theme or implement access control mitigation rules.

Affected products

  • extendthemes Vireo <= 1.0.37

Timeline

  • 2025-10-20: disclosed: Vulnerability reported to Patchstack
  • 2025-12-31: advisory: Published by Patchstack and disclosed publicly

References