Junglewise Threat Intelligence

CVE-2026-24586: Themeansar Newses missing authorization in WordPress theme

CVE-2026-24586 · Severity: medium · CVSS 5.4 · Published 2026-05-25

Executive brief

The Newses theme for WordPress contains a security flaw where it fails to properly check user permissions for certain actions. This could allow a logged-in user with low-level access, such as a subscriber, to perform actions or modify settings that should be restricted to administrators. While the impact is considered moderate, it could lead to unauthorized changes to the website's configuration or content.

Technical details

A missing authorization vulnerability (CWE-862) exists in the Themeansar Newses theme for WordPress through version 2.0.0.77. The issue stems from incorrectly configured access control security levels, where the application fails to validate if a user has the necessary privileges before executing specific functions. An attacker authenticated with low-level privileges (Subscriber) can exploit this over the network to perform actions that should be restricted to higher-privileged roles. This can result in unauthorized modifications to site data or settings. As of the advisory date, no official patch has been released.

Affected products

  • Themeansar Newses n/a through 2.0.0.77

Timeline

  • 2025-12-19: other: Vulnerability reported by researcher
  • 2026-05-25: disclosed: Vulnerability published by Patchstack
  • 2026-05-25: advisory: NVD published CVE-2026-24586

References