Junglewise Threat Intelligence

CVE-2026-57405: ThemeHunk Open Shop missing authorization in WordPress theme

CVE-2026-57405 · Severity: high · CVSS 7.1 · Published 2026-07-13

Vendors: ThemeHunk.

Executive brief

The Open Shop theme for WordPress, which is used to build e-commerce websites, contains a security flaw in its access control settings. This vulnerability allows logged-in users with low-level permissions, such as customers or subscribers, to perform actions they should not be authorized to do. An exploit could lead to unauthorized changes to the website's configuration or cause service disruptions, potentially impacting store operations and reputation.

Technical details

A Broken Access Control vulnerability (CWE-862) exists in the ThemeHunk Open Shop theme through version 1.7.1. The flaw stems from missing authorization checks or incorrectly configured access control levels within the theme's functions. An attacker authenticated with basic 'Subscriber' privileges can exploit this to execute higher-privileged actions. While the specific functions affected are not detailed, the CVSS vector indicates a high impact on availability and a low impact on integrity. The issue is resolved in version 1.7.2.

Affected products

  • ThemeHunk Open Shop <= 1.7.1

Timeline

  • 2026-04-29: disclosed: Reported by HaiND to Patchstack
  • 2026-07-08: advisory: Patchstack published advisory
  • 2026-07-13: advisory: NVD published CVE record
  • 2026-07-13: patched: Version 1.7.2 confirmed as patched version

References