Junglewise Threat Intelligence

CVE-2026-57689: Fuelthemes Werkstatt broken access control in WordPress theme

CVE-2026-57689 · Severity: medium · CVSS 4.3 · Published 2026-07-02

Technologies: Fuelthemes Werkstatt. Vendors: Fuelthemes.

Executive brief

The Werkstatt theme for WordPress contains a security flaw that allows users with low-level 'Subscriber' accounts to access information or perform actions they should not be authorized to see. This could lead to unauthorized data exposure or minor configuration changes on websites using this theme. While the impact is considered low, it represents a failure in the theme's permission system.

Technical details

A broken access control vulnerability exists in the Fuelthemes Werkstatt theme for WordPress through version 4.7.2. The issue stems from missing authorization checks (CWE-862) in certain theme functions, which fail to validate the user's permission level before executing actions or returning data. An attacker authenticated with a low-privilege account, such as a Subscriber, can exploit this over the network to access restricted functionality. As of the advisory date, no official patch has been released.

Affected products

  • Fuelthemes Werkstatt <= 4.7.2

Timeline

  • 2024-09-17: other: Reported by researcher Ananda Dhakal
  • 2026-06-29: advisory: Published by Patchstack
  • 2026-07-02: disclosed: NVD publication date

References

Related threats