Executive brief
A security flaw exists in the Martfury WordPress theme, which is used to build online marketplaces. This vulnerability allows users with basic 'Subscriber' accounts to perform actions they should not be authorized to do. While the impact is considered low, it could allow unauthorized changes to site settings or data depending on the specific functions exposed.
Technical details
A broken access control vulnerability (CWE-862: Missing Authorization) exists in the Martfury - WooCommerce Marketplace WordPress Theme through version 3.2.8. The issue stems from a lack of proper authorization or nonce validation in certain theme functions. An attacker authenticated with low-level 'Subscriber' privileges can exploit this over the network to execute actions that should be restricted to higher-privileged users. As of the advisory date, no official patch has been released.
Affected products
- drfuri Martfury - WooCommerce Marketplace WordPress Theme <= 3.2.8
Timeline
- 2024-09-17: disclosed: Reported by Ananda Dhakal via Patchstack
- 2026-06-29: advisory: Published by Patchstack
- 2026-07-02: other: NVD published date