Junglewise Threat Intelligence

CVE-2026-57774: vowelweb VW Food Corner missing authorization in WordPress theme

CVE-2026-57774 · Severity: medium · CVSS 5.3 · Published 2026-07-13

Executive brief

VW Food Corner, a WordPress theme designed for food-related websites, contains a security flaw in its access control settings. This vulnerability could allow an unauthorized person to perform actions that should be restricted to administrators or specific users. While the impact is currently rated as low, it could potentially lead to service disruptions or unauthorized changes to the website's configuration.

Technical details

A Missing Authorization (CWE-862) vulnerability exists in the vowelweb VW Food Corner theme for WordPress through version 1.1.0. The flaw stems from incorrectly configured access control security levels, which fail to properly validate user permissions before executing certain functions. An unauthenticated remote attacker can exploit this to perform actions that should require higher privilege levels. According to the CVSS vector, the primary impact is a partial loss of availability. As of the advisory date, no official patch has been released.

Affected products

  • vowelweb VW Food Corner <= 1.1.0

Timeline

  • 2026-01-31: disclosed: Reported by Nabil Irawan to Patchstack
  • 2026-07-02: advisory: Initial advisory published by Patchstack
  • 2026-07-13: advisory: CVE published to NVD dataset

References