Executive brief
The Woostify Sites Library plugin for WordPress, which provides pre-built website templates, contains a security flaw that allows unauthorized users to perform actions they should not have access to. An attacker could potentially modify site settings or trigger plugin functions without needing to log in. This could lead to unauthorized changes to the website's configuration or appearance.
Technical details
The Woostify Sites Library plugin for WordPress is vulnerable to broken access control due to missing authorization checks (CWE-862) in certain functions. This allows an unauthenticated remote attacker to execute actions that should be restricted to administrative users. The vulnerability stems from a lack of proper capability checks or nonce validation, enabling unauthorized integrity-related changes. As of the latest advisory, no official patch has been confirmed, and users are advised to monitor for updates from the developer.
Affected products
- Dylan Ngo Woostify Sites Library <= 1.6.2
Timeline
- 2025-10-21: other: Reported by researcher Legion Hunter
- 2026-06-29: advisory: Initial advisory published by Patchstack
- 2026-07-02: disclosed: CVE published to NVD dataset