Executive brief
KuteShop is a WordPress theme used to build e-commerce websites. A security flaw in the theme allows unauthorized individuals to bypass access controls, potentially leading to the execution of restricted commands or access to internal site features. This could allow an attacker to interfere with site operations or view information they should not have access to.
Technical details
A Missing Authorization (CWE-862) vulnerability exists in the KuteShop theme for WordPress through version 4.2.9. The flaw stems from a failure to implement proper authorization checks or nonce validation on certain functions, which can lead to arbitrary shortcode execution. An unauthenticated remote attacker can exploit this by sending crafted requests to the site, potentially allowing them to execute actions that should be restricted to higher-privileged users. As of the latest advisory, no official patch has been released.
Affected products
- kutethemes KuteShop <= 4.2.9
Timeline
- 2026-01-10: other: Vulnerability reported by researcher João Pedro S Alcântara
- 2026-02-09: disclosed: Initial disclosure by Patchstack
- 2026-04-08: advisory: CVE published in NVD