Executive brief
Metro Magazine, a popular WordPress theme used for news and magazine-style websites, contains a security flaw in its access control settings. This vulnerability allows unauthorized individuals to perform actions that should be restricted to administrators or site owners. An attacker could potentially modify site settings or disrupt operations, leading to a loss of site integrity and availability.
Technical details
A missing authorization vulnerability (CWE-862) exists in the Rara Themes Metro Magazine theme for WordPress up to version 1.4.1. The flaw stems from incorrectly configured access control security levels, which fail to properly validate user permissions before executing certain functions. An unauthenticated remote attacker can exploit this by sending crafted requests to the server, allowing them to perform actions that should require higher privileges. This can result in unauthorized modifications to site data or a partial denial of service. The issue is resolved in version 1.4.2.
Affected products
- Rara Themes Metro Magazine n/a through 1.4.1
Timeline
- 2026-01-12: other: Reported by researcher Trương Hữu Phúc
- 2026-04-23: disclosed: Initial disclosure by Patchstack
- 2026-04-23: patched: Version 1.4.2 released to address the vulnerability
- 2026-06-16: advisory: CVE published to NVD dataset