Executive brief
The Ashe theme for WordPress, used for website design and layout, contains a security flaw in its access control settings. An attacker with a basic user account could exploit this to perform actions they should not be authorized to do. This could lead to unauthorized changes to website settings or content, potentially impacting the site's integrity.
Technical details
A missing authorization (CWE-862) vulnerability exists in the WP Royal Ashe theme for WordPress through version 2.267. The flaw stems from incorrectly configured access control security levels, which fail to properly validate user permissions before executing certain functions. An attacker authenticated with low-level privileges, such as a Subscriber, can exploit this vulnerability over the network to perform actions typically reserved for higher-privileged users. The issue is resolved in version 2.268.
Affected products
- WP Royal Ashe <= 2.267
Timeline
- 2026-01-13: other: Vulnerability reported by researcher
- 2026-02-12: advisory: Patchstack advisory published
- 2026-04-08: disclosed: CVE published