Executive brief
NanoCare, a WordPress theme used for website design, contains a security flaw where it fails to properly check user permissions. This allows a logged-in user with low-level access, such as a subscriber, to perform actions or modify settings that should be restricted to administrators. While the impact on data privacy is low, it could lead to unauthorized changes to the website's configuration or availability.
Technical details
A missing authorization vulnerability (CWE-862) exists in the Linethemes NanoCare theme for WordPress in versions prior to 1.2.2. The flaw stems from incorrectly configured access control security levels, which fail to validate the authorization of users before executing certain functions. An attacker authenticated with low-level privileges (such as a 'Subscriber') can exploit this over the network to perform actions that should require higher administrative permissions. This can result in unauthorized integrity changes or service disruptions, though it does not directly facilitate data exfiltration. The issue is resolved in version 1.2.2.
Affected products
- Linethemes NanoCare before 1.2.2
Timeline
- 2026-01-20: other: Reported by researcher Phat RiO
- 2026-05-25: advisory: Published by Patchstack and NVD
- 2026-05-25: patched: Fixed in version 1.2.2