Junglewise Threat Intelligence

CVE-2026-57776: vowelweb VW Wedding missing authorization in WordPress theme

CVE-2026-57776 · Severity: medium · CVSS 5.3 · Published 2026-07-13

Executive brief

The VW Wedding theme for WordPress contains a security flaw where it fails to properly check user permissions for certain actions. This could allow an unauthorized person to perform tasks or access settings that should be restricted to site administrators. While the reported impact is currently limited, it represents a breakdown in the website's security boundaries.

Technical details

A Missing Authorization (CWE-862) vulnerability exists in the vowelweb VW Wedding theme for WordPress through version 1.3.7. The flaw stems from a failure to implement proper permission checks or nonce validation on certain functions, leading to broken access control. An unauthenticated remote attacker can exploit this to execute actions that should be restricted to higher-privileged users. According to the CVSS vector, the primary impact is a partial loss of availability. As of the advisory date, no official patch has been released.

Affected products

  • vowelweb VW Wedding <= 1.3.7

Timeline

  • 2026-01-30: other: Reported by Nabil Irawan
  • 2026-07-02: advisory: Initial disclosure by Patchstack
  • 2026-07-13: disclosed: CVE published to NVD dataset

References