Executive brief
The Genemy theme for WordPress, used to design and manage website layouts, contains a security flaw in its access control mechanisms. This vulnerability allows a user with basic 'Subscriber' permissions to perform actions that should be restricted to higher-level administrators. An attacker could exploit this to modify website settings or content, potentially leading to unauthorized changes to the site's appearance or functionality.
Technical details
A broken access control vulnerability exists in the Jthemes Genemy theme for WordPress (versions up to and including 1.6.6) due to missing authorization checks (CWE-862). The flaw allows a remote attacker with Subscriber-level authentication to bypass intended access restrictions and execute functions that should be reserved for higher-privileged roles. According to the CVSS vector, the attack has high integrity impact but no impact on confidentiality or availability. As of the advisory date, no official patch has been released, and users are advised to seek mitigation through security rules or alternative themes.
Affected products
- Jthemes Genemy <= 1.6.6
Timeline
- 2025-10-28: other: Vulnerability reported by researcher
- 2026-05-26: advisory: Patchstack advisory published
- 2026-06-17: disclosed: CVE published to NVD