Executive brief
The Education Base theme for WordPress, used to build educational and institutional websites, contains a security flaw in its access control settings. This vulnerability allows unauthenticated visitors to perform actions that should be restricted to authorized administrators. While the impact is considered moderate, it could allow unauthorized changes to site settings or content, potentially affecting the site's integrity.
Technical details
A Missing Authorization (CWE-862) vulnerability exists in the Acme Themes Education Base theme for WordPress through version 3.0.8. The flaw stems from incorrectly configured access control security levels, which fail to properly validate user permissions before executing certain functions. An unauthenticated remote attacker can exploit this to perform actions that should require higher privileges. The vulnerability is addressed in version 4.0.0.
Affected products
- Acme Themes Education Base <= 3.0.8
Timeline
- 2026-01-12: other: Vulnerability reported by researcher
- 2026-02-11: disclosed: Initial disclosure by Patchstack
- 2026-04-08: advisory: CVE published to NVD
- 2026-02-11: patched: Version 4.0.0 released to address the issue