Executive brief
The Biolife WordPress theme by kutethemes contains a security flaw where it fails to properly check user permissions. This allows unauthorized individuals to execute arbitrary shortcodes, which could lead to the exposure of sensitive information or unauthorized changes to website content. This vulnerability impacts the overall security and integrity of websites using this theme for their online stores.
Technical details
A Missing Authorization (CWE-862) vulnerability in the kutethemes Biolife theme for WordPress (versions up to and including 3.2.3) allows for arbitrary shortcode execution. The issue stems from incorrectly configured access control security levels that fail to validate user privileges before processing certain functions. An unauthenticated remote attacker can exploit this flaw to execute shortcodes, potentially leading to information disclosure or unauthorized site modifications. As of the advisory date, no official patch has been released.
Affected products
- kutethemes Biolife <= 3.2.3
Timeline
- 2026-01-12: other: Vulnerability reported by researcher João Pedro S Alcântara (Kinorth)
- 2026-02-11: disclosed: Initial disclosure by Patchstack
- 2026-04-08: advisory: CVE published to NVD