Junglewise Threat Intelligence

CVE-2026-27364: AnalogWP Style Kits broken access control in subscriber role

CVE-2026-27364 · Severity: medium · CVSS 6.5 · Published 2026-08-24

Technologies: AnalogWP Style Kits. Vendors: AnalogWP.

Executive brief

Style Kits is a WordPress plugin that allows website designers to create and manage custom style templates. Versions up to 2.6.5 contain a broken access control vulnerability that allows subscriber-level users to access or perform actions they should not be permitted to perform. An attacker with a subscriber account (the lowest privilege level) could exploit this to view restricted content or perform privileged actions on the WordPress site.

Technical details

This vulnerability is a broken access control flaw in the AnalogWP Style Kits WordPress plugin affecting versions 2.6.5 and earlier. The vulnerability requires subscriber-level privileges to exploit, indicating insufficient permission checks in the plugin's code. An authenticated attacker with a subscriber account can bypass access controls to perform actions or view data that should be restricted to higher-privilege users (such as administrators or editors). The vulnerability is tracked as CVE-2026-27364 with a CVSS score of 6.5. The plugin maintainers released a patch in version 2.6.6 addressing this access control issue.

Affected products

  • AnalogWP Style Kits <=2.6.5

Timeline

  • 2026-08-24: disclosed
  • 2026-08-24: patched: Version 2.6.6 released

References

Related threats