Junglewise Threat Intelligence

CVE-2025-66076: Dylan Ngo Woostify Sites Library broken access control

CVE-2025-66076 · Severity: medium · CVSS 5.3 · Published 2026-07-02

Executive brief

The Woostify Sites Library plugin for WordPress, which provides pre-built website templates, contains a security flaw that allows unauthorized users to perform actions they should not have access to. An attacker could potentially modify site settings or trigger plugin functions without needing to log in. This could lead to unauthorized changes to the website's configuration or appearance.

Technical details

The Woostify Sites Library plugin for WordPress is vulnerable to broken access control due to missing authorization checks (CWE-862) in certain functions. This allows an unauthenticated remote attacker to execute actions that should be restricted to administrative users. The vulnerability stems from a lack of proper capability checks or nonce validation, enabling unauthorized integrity-related changes. As of the latest advisory, no official patch has been confirmed, and users are advised to monitor for updates from the developer.

Affected products

  • Dylan Ngo Woostify Sites Library <= 1.6.2

Timeline

  • 2025-10-21: other: Reported by researcher Legion Hunter
  • 2026-06-29: advisory: Initial advisory published by Patchstack
  • 2026-07-02: disclosed: CVE published to NVD dataset

References