Executive brief
The Flipmart theme for WordPress contains a security flaw where it fails to properly check user permissions for certain actions. This could allow an unauthorized person to access information or perform actions that should be restricted to administrators. While the impact is considered moderate, it could lead to unauthorized changes or data exposure on websites using this theme.
Technical details
A Missing Authorization (CWE-862) vulnerability exists in the CKThemes Flipmart theme for WordPress through version 2.8. The issue stems from incorrectly configured access control security levels, where the application fails to validate if a user has the necessary privileges before executing specific functions. An unauthenticated remote attacker can exploit this flaw to bypass intended access restrictions. Depending on the specific functions exposed, this could lead to unauthorized data retrieval or modification. As of the advisory date, no official patch has been released.
Affected products
- CKThemes Flipmart <= 2.8
Timeline
- 2026-01-31: other: Vulnerability reported by researcher João Pedro S Alcântara
- 2026-03-02: advisory: Patchstack published advisory
- 2026-04-08: disclosed: CVE published to NVD