Executive brief
Style Kits is a WordPress plugin that allows website designers to create and manage custom style templates. Versions up to 2.6.5 contain a broken access control vulnerability that allows subscriber-level users to access or perform actions they should not be permitted to perform. An attacker with a subscriber account (the lowest privilege level) could exploit this to view restricted content or perform privileged actions on the WordPress site.
Technical details
This vulnerability is a broken access control flaw in the AnalogWP Style Kits WordPress plugin affecting versions 2.6.5 and earlier. The vulnerability requires subscriber-level privileges to exploit, indicating insufficient permission checks in the plugin's code. An authenticated attacker with a subscriber account can bypass access controls to perform actions or view data that should be restricted to higher-privilege users (such as administrators or editors). The vulnerability is tracked as CVE-2026-27364 with a CVSS score of 6.5. The plugin maintainers released a patch in version 2.6.6 addressing this access control issue.
Affected products
- AnalogWP Style Kits <=2.6.5
Timeline
- 2026-08-24: disclosed
- 2026-08-24: patched: Version 2.6.6 released