Executive brief
Woffice is a popular WordPress theme used to build intranets and community websites. A security flaw in the theme's access control settings could allow unauthorized individuals to perform actions that should be restricted to higher-privileged users. This could lead to unauthorized changes to the site's configuration or content, though the overall risk is currently considered low.
Technical details
A broken access control vulnerability exists in the Woffice WordPress theme due to missing authorization checks in certain functions. An unauthenticated remote attacker can exploit this flaw to execute actions that are intended for users with higher privilege levels. The root cause is an incorrect configuration of access control security levels within the theme's logic. The vulnerability is addressed in version 5.4.33, and users are advised to update to the latest version to mitigate the risk of unauthorized administrative actions.
Affected products
- WofficeIO Woffice before 5.4.33
Timeline
- 2025-10-13: disclosed: Reported by João Pedro S Alcântara (Kinorth)
- 2026-06-29: patched: Patch released in version 5.4.33
- 2026-06-29: advisory: Early warning and publication by Patchstack
- 2026-07-01: advisory: NVD publication date