Executive brief
The Royale News theme for WordPress contains a security flaw where it fails to properly verify user permissions for certain actions. This could allow an unauthorized visitor to perform administrative or restricted tasks on the website, potentially altering site settings or content. Because the theme has not been updated in over a year, a formal fix is unlikely, and site owners are advised to switch to a supported theme.
Technical details
A Missing Authorization (CWE-862) vulnerability exists in the themebeez Royale News theme for WordPress through version 2.2.4. The flaw stems from incorrectly configured access control security levels, which fail to validate if a user has the necessary privileges before executing specific functions. An unauthenticated remote attacker can exploit this over the network to perform unauthorized actions that should be restricted to higher-privileged users. As of the advisory date, no official patch is available, and the software is considered end-of-life.
Affected products
- themebeez Royale News <= 2.2.4
Timeline
- 2026-01-16: other: Reported by Legion Hunter
- 2026-02-15: advisory: Initial disclosure by Patchstack
- 2026-04-08: disclosed: CVE published to NVD