Executive brief
A security flaw has been identified in the WordPress Dating Theme, a popular template used to build dating and community websites. This vulnerability allows unauthorized individuals to bypass security checks and perform actions or access data that should be restricted to administrators. If exploited, this could lead to the exposure of sensitive user information or unauthorized changes to the website's configuration and content.
Technical details
A broken access control vulnerability (CWE-862) exists in the PremiumPress WordPress Dating Theme (DA10) through version 11.2.0. The flaw stems from missing authorization or nonce checks in certain functions, allowing an unauthenticated remote attacker to execute privileged actions. With a CVSS score of 8.6, the vulnerability provides a high impact on confidentiality and a partial impact on integrity and availability. As of the advisory date, no official patch has been released by the vendor, and users are advised to use third-party mitigation rules or monitor for updates.
Affected products
- PremiumPress Limited. WordPress Dating Theme (DA10) <= 11.2.0
Timeline
- 2025-11-23: other: Vulnerability reported by researcher 0xd4rk5id3
- 2026-02-09: advisory: Initial advisory published by Patchstack
- 2026-06-17: disclosed: CVE published and NVD record created